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[Krebs  on  Security]  'BlueLeaks'  Exposes  Files  from  Hundreds  of  Police 
Departments 

From:  KrebsOnSecurity  Mailing  List  <bk@krebsonsecurity.com> 

To:  bk@krebsonsecurity.com 

Sent:  June  21 , 2020  1 1 :33:26  PM  CDT 

Received:  June  21 , 2020  1 1 :35:18  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when  opening 
attachments,  clicking  links,  or  responding  to  this  email. 

Krebs  on  Security  has  posted  a  new  item. 

Hundreds  of  thousands  of  potentially  sensitive  files  from  police  departments 
across  the  United  States  were  leaked  online  last  week.  The  collection,  dubbed 
"BlueLeaks"  and  made  searchable  via  a  new  website  by  the  same  name,  stems  from 
a  security  breach  at  a  Texas  web  design  and  hosting  company  that  maintains  a 
number  of  state  law  enforcement  data-sharing  portals  online. 

https://krebsonsecurity.com/2020/06/blueleaks-exposes-files-from-hundreds-of-police-departments/ 
Please  use  the  link  above  to  continue  reading  this  posting. 


Survey  Report:  SANS  Automation  and  Integration  Survey 

The  goal  of  the  Automation  and  Integration  Survey  is  to  quantify  automation 
experiences  to  better  understand  how  organizations  can  maximize  their  security 
investment  while  improving  operations  through  automation  efforts.  The  survey 
looked  at  what  automation  activities  have  been  successful,  why  they  were 
successful,  and  how  organizations  approached  their  automation  activities  to 
achieve  meaningful  results.  Discover  the  trends  and  themes  that  emerged  from 
this  year's  survey. 

Download  Now: 

https://www.krebsonsecurity.com/domaintools/ 


You  received  this  e-mail  because  you  asked  to  be  notified  when  new  updates  are 
posted. 

Best  regards, 

BrianKrebs 

https://krebsonsecurity.com 


P.S.  You  may  manage  your  subscription  here: 
https://krebsonsecurity.com/subscribe/ 
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From:  OODA  Loop  <loop@ooda.com> 

To:  myron.weres@cookcountyil.gov,  Myron  Weres  (Sheriff) 

<Myron.Weres@cookcountyil.gov> 

Sent:  June  22,  2020  9:01 :15  AM  CDT 

Received:  June  22,  2020  9:01 :26  AM  CDT 


External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
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OODA  ORIGINAL  ANALYSIS 

The  latest  original  analysis  and  research  available  exclusively  at  OODALoop.com. 

•  OODA  Video:  The  Technologies  of  Al  Security  and  Ethics 


•  OODA  Network  Interview:  Dr.  Gaurav  Banga 


CYBER  THREAT  BRIEF 

The  latest  cyber  threat  and  risk  news. 

Google  Yanks  106  ‘Malicious’  Chrome  Extensions 

On  Thursday,  Google  removed  over  100  Chrome  browser  extensions  that  it  found  to  be  malicious, 
after  reports  that  they  were  being  used  to  siphon  sensitive  user  data.  Google  also  published  the 
research  behind  the  apps,  in  which  Awake  Security  alleges  millions  of  Chrome  users  have  been 
targeted  by  threat  actors.  |  (Read  More) 

Hacker  arrested  for  stealing,  selling  Pll  of  65K  hospital  employees 

Justin  Sean  Johnson,  a  29-year-old  man  from  Michigan,  was  arrested  earlier  this  week  for  his 


involvement  in  a  2014  hack  of  the  health  care  provider  University  of  Pittsburg  Medical  Center 
(UPMC).  Johnson  allegedly  executed  the  attack  and  stole  personally  identifiable  information  and  W-2 
information  of  over  65,000  employees.  Johnson  is  |  (Read  More) 

Data  from  200  US  police  departments  &  fusion  centers  published  online 

On  Friday,  an  activist  group  that  describes  itself  as  a  transparency  collective  published  296GB  of 
data  that  appears  to  have  been  stolen  from  US  law  enforcement  agencies  and  fusion  centers.  The 
massive  data  leak  has  been  named  BlueLeaks  and  was  published  by  the  group  Distributed  Denial  of 
Secrets  (DDoSecrets).  The  |  (Read  More) 

Facebook  Pulls  Trump  Campaign  Ad  Featuring  Nazi  Symbol 

Facebook  has  made  the  decision  to  remove  advertising  for  Donald  Trump’s  re-election  campaign 
because  it  featured  a  symbol  that  is  heavily  associated  with  Nazi  Germany.  The  advertisements, 
which  stated  that  left-wing  activists  he  calls  Antifa  should  be  branded  a  terrorist  organization,  had  an 
inverted  red  triangle.  The  inverted  red  triangle  |  (Read  More) 

Sophisticated  State-Backed  Attack  Rocks  Australia 

Today,  Australian  Prime  Minister  Scott  Morrison  warned  of  a  high  threat  state-sponsored  cyber 
espionage  campaign  targeting  both  the  government  and  private  sector  within  the  country.  Morrison 
urged  domestic  organizations  to  improve  their  security  practices  such  as  enabling  multi-factor 
authentication  and  installing  released  patches  immediately.  Morrison  also  stated  that  the  threatening 

|  (Read  More) 


GLOBAL  RISK  BRIEF 

The  latest  global  risk  news. 

As  virus  spikes,  Pakistan  says  there’s  no  choice  but  to  open 

In  Pakistan,  COVID-19  is  spreading  at  one  of  the  fasted  rates  in  the  world,  and  hospitals  can’t  keep 
up.  Health  care  facilities  have  been  turning  away  patients  as  they  continue  to  receive  hundreds  of 
COVID-19  patients  per  day.  However,  the  government  is  moving  forward  with  opening  up  the  country 

due  |  (Read  More) 

Brazil  becomes  second  country  to  pass  50,000  deaths 

Brazil  has  recently  become  the  second  country  to  reach  more  than  50,000  COVID-19  related  deaths, 
following  the  US  in  terms  of  the  highest  infection  and  death  rates.  This  milestone  comes  amid 
growing  political  tension  and  just  a  few  days  after  officials  confirmed  more  than  one  million  COVID-19 
infections  within  the  |  (Read  More) 


A  new  threat  to  global  trade,  Exhausted  crews  want  off  cargo  ships  now 

Global  trade  is  facing  another  economic  crisis  due  to  the  COVID-19  pandemic,  as  seafarers  stranded 
for  months  due  to  port  closures  could  refuse  to  keep  working.  Many  cargo  ship  crew  extended  their 


contracts  by  several  months  to  continue  to  supplies  of  food,  fuel,  and  medicine  flowing  around  the 
world  during  |  (Read  More) 


China  charges  2  Canadians  with  spying  in  Huawei-linked  case 

Today,  two  Canadians  detained  in  China  were  charged  with  spying  in  a  bid  to  step  up  pressure  on 
Canada  to  drop  the  US’s  extradition  request  for  prominent  Huawei  employee  who  is  currently  serving 
house  arrest  in  Vancouver.  One  of  the  Canadians,  Michael  Kovrig,  was  charged  by  china  on 
suspicion  of  |  (Read  More) 


Coronavirus  was  already  in  Italy  by  December,  waste  water  study  finds 

Italian  officials  say  that  the  COVID-19  virus  was  present  in  the  country  in  December,  after  the 
National  Institute  of  Health  stated  that  water  from  Milan  and  Turin  showed  genetic  traces  of  the  virus 
on  December  18.  This  adds  to  the  increasing  amount  of  evidence  that  the  virus  has  been  circulating  | 

(Read  More) 


TECHNOLOGY  BRIEF 

The  important  technology  news. 


Nextdoor  eliminates  its  Forward  to  Police  program 

Nextdoor,  a  neighborhood  social  networking  app  has  announced  that  they  are  discontinuing  their 
Forward  to  Police  feature  that  allowed  users  to  send  message  board  posts  directly  to  the  local  police 
department.  The  platform  has  been  controversial  lately  for  how  it  handles  communications  with  law 
enforcement  and  racism  among  members  of  |  (Read  More) 

Robot  Divers  Could  Use  Artificial  Intelligence  To  Save  Coral  Reefs 

A  National  Oceanic  and  Atmospheric  Administration  organization  claims  that  humans  will  not  be  able 
to  save  the  coral  reefs  dying  at  an  alarming  rate  across  the  globe.  In  optimal  conditions,  human 
divers  can  still  only  spend  three  to  four  hours  per  day  working  underwater  in  restoration  efforts.  Tom 
Moore,  program  |  (Read  More) 

NIH  Partners  with  Israeli  Startup  to  Generate  Synthetic  COVID-19  Data 

On  Thursday,  the  National  Institutes  of  Health  announced  a  new  partnership  with  Israeli  startup 
MDCIone.  The  collaboration  is  an  attempt  to  generate  computationally  derived  synthetic  data  from 
aggregated  clinical  health  data.  The  data  will  be  utilized  to  advance  COVID-19  research.  This  is  a 
new  development  in  the  NIH’s  National  COVID  |  (Read  More) 

Air  Force  Awards  Anchore  Phase  II  Contract  to  Advance  DevSecOps 

The  Air  Force  has  awarded  Anchore,  a  security  solution  provider,  a  phase  II  Small  Business 
Innovation  Research  contract  of  $2.25  million.  The  award  aims  to  boost  DevSecOps-centered 
technology.  A  spokesperson  for  Anchore  stated  that  they  are  excited  to  pioneer  developments  in  the 
journey  for  wide-scale  software  application  modernization  across  government  |  (Read  More) 


Pentagon  Unveils  New  Defense  Space  Strategy 

On  June  17,  the  Pentagon  unveiled  a  new  Defense  Space  Strategy  that  aims  to  ensure  the  US 
maintains  military  superiority  over  advanced  adversaries  such  as  China  and  Russia.  The  new  plan 
signifies  the  critical  moment  in  space  exploration  that  we  are  currently  in.  The  US  military  is  also 
increasingly  shifting  |  (Read  More) 


OODA  Loop  Daily  Pulse 

This  OODA  Loop  Daily  brief  is  a  hand-curated  cyber  and  risk  intelligence  briefing  covering  the 
latest  global  threats  and  risk  issues.  For  more  information  visit  www.oodaloop.com 
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The  CyberWire  6.22.20:  BlueLeaks 
dumps  decades  of  police  files.  BlueKai 
data  leaked.  COVID-19  app  privacy. 
Cyber  conflict:  China  vs.  India, 
Australia? 

From:  The  CyberWire  <editor@thecyberwire.com> 

To:  Keith.Morrison@cookcountyil.gov,  Keith  Morrison  (Sheriff) 
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External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when  opening 
attachments,  clicking  links,  or  responding  to  this  email. 


More  signal,  less  noise. 


■ 


SPONSORED  BY  RECORDED  FUTURE: 

Get  real-time  security  intelligence  at  no  cost. 

We  recently  launched  Recorded  Future  Express  —  a  free  browser  extension  for  security 
teams.  Use  Express  over  any  web-based  SIEM,  vulnerability  management  solution,  security 
blog,  and  more  to  put  real-time  security  intelligence  at  your  fingertips.  Instantly  prioritize 
alerts,  incidents,  and  vulnerabilities  based  on  real-time  risk  scores  from  the  world’s  largest 
commercial  collection  platform.  Sign  up  now. 


Daily  briefing. 

June  22,  2020. 


SUMMARY 


By  the  CyberWire  staff 


Distributed  Denial  of  Secrets  (DDoSecrets),  a  hacktivist  group  described  as  an  alternative  to 
WikiLeaks,  has  posted  BlueLeaks,  "ten  years  of  data  from  over  200  police  departments, 
fusion  centers  and  other  law  enforcement  training  and  support  resources.  Among  the 
hundreds  of  thousands  of  documents  are  police  and  FBI  reports,  bulletins,  guides  and  more." 
The  files  are  available,  KrebsOnSecurityreports,  in  a  searchable  database.  The  National 
Fusion  Center  Association  (NFCA)  has  confirmed  the  data's  validity,  saying  the  leaked  files 
were  compiled  between  August  1996  and  June  19,  2020,  which  covers  more  than  the  decade 
DDoSecrets  claimed  in  their  tweeted  communique.  The  breach  appears  to  originate  with  a 
third  party:  NCFA  believes  the  data  were  probably  taken  from  Netsential  (a  contractor  widely 
used  by  state  fusion  centers)  by  someone  who  gained  entrance  to  the  system  using 
compromised  user  credentials. 

TechCrunch  reports  that  data  collected  on  behalf  of  clients  by  Oracle's  BlueKai,  which  uses 
cookies  and  "other  tracking  tech"  to  follow  users  as  they  browse  the  web,  the  better  to 
develop  profiles  for  marketing,  were  exposed  in  unsecured  servers.  Oracle  believes  the 
incident  to  be  a  misconfigu ration  issue  on  the  part  of  two  of  its  customers 

The  Washington  Post  summarizes  two  examinations  of  widely  used  COVID-19  contact-tracing 
and  symptom-logging  apps.  Many  are  weakly  encrypted,  and  several  arguably  overshare  data 
with  third  parties. 

India  remains  jittery  over  the  prospect  of  Chinese  cyberattacks,  ET  CIO  reports.  And  judging 
from  stories  in  the  Australian  Financial  Review  and  elsewhere,  Australia  remains  in  high 
dudgeon  over  Chinese  government  hacking. 

[250] 


SPONSORED  BY  GDIT: 

Secure  your  mission  with  the  GDIT  Cyber  Stack,  our  ecosystem  of  cyber 

capabilities. 


Notes. 

Today's  issue  includes  events  affecting  Australia,  Canada,  China,  the  European  Union, 
France,  India,  Indonesia,  Iran,  Ireland,  the  Democratic  People's  Republic  of  Korea,  the 
Republic  of  Korea,  Morocco,  the  Netherlands,  New  Zealand,  Pakistan,  the  Philippines, 

Russia,  the  United  Kingdom,  and  the  United  States. 

CSO  Perspectives:  Cyber  Threat  Intelligence,  the 
fuel  that  drives  the  entire  infosec  engine. 

By  Rick  Floward,  CSO,  Chief  Analyst,  and  Senior  Fellow,  The  CyberWire 

Zero  trust,  intrusion  kill  chains,  resilience,  DevSecOps,  and  risk  assessment  are  essential  key 
strategies  for  preventing  material  impact  to  our  organization  due  to  a  cyber  event.  The  fuel 


that  drives  that  engine  is  cyber  threat  intelligence  operations. 

This  week,  we’re  talking  about  cyber  threat  intelligence  in  CyberWire  Pro.  Be  sure  to  check 
out  the  essay  and  the  accompanying  podcast  called  Cybersecurity  first  principles:  cyber  threat 
intelligence  operations  on  the  CSO  Perspectives  section  of  the  CyberWire  Website. 


SPONSORED  BY  MCAFEE: 

Transition  your  enterprise  to  a  secured,  remote  work  environment 
with  McAfee 

Most  companies  aren’t  prepared  to  secure  data  and  assets  for  a  surge  of  remote  employees. 
Whether  your  VPN  is  over  capacity,  new  cloud  services  are  coming  on-board,  or  new  devices 
need  protection,  we  have  you  covered  during  this  critical  time.  McAfee  is  offering  3-month 
subscriptions  for  Endpoint  Protection,  Unified  Cloud  Edge,  and  CASB  to  help  you  scale 
security  to  your  remote  employees.  Learn  more  about  these  offers 
at  mcafee.com/workfromhome. 


ON  THE  PODCAST 


In  today's  CyberWire  Daily  Podcast,  out  later  this  afternoon,  we  speak  with  Rick  Howard,  the 
CyberWire's  CSO  and  Chief  Analyst,  who  discusses  intelligence  operations  and  introduces 
Canon  Week.  Our  inaugural  Canon  Week  guest  is  Todd  Fitzgerald,  author  of  CISO  Compass, 
a  book  about  the  challenges  of  cybersecurity  leadership,  with  lessons  learned  from  those 
who've  met  those  challenges. 


SPONSORED  EVENTS 


Cyber  Security  Summit  Virtual  Power  Hours  (Online,  June  23  -  25,  2020)  Senior  Level 
Executives  are  invited  to  the  Cyber  Summit  Virtual  Power  Hours.  Learn  from  Industry  Experts 
from  The  FBI,  DHS,  U.S.  Secret  Service  &  leading  cyber  solution  providers  as  they  discuss 
the  latest  security  challenges  &  develop  cyber  security  battle  plans  in  today’s  unprecedented 
times.  You  will  receive  1  CPE  /  CEU  credit  by  attending.  Free  to  register  with  code: 
CyberWire20  at  CyberSummitUSA.com. 

Improving  Cyber-Oriented  Education  (Online,  June  25,  2020)  The  Cyberspace  Solarium 
Commission  (CSC)  recently  released  a  report  that  proposes  a  strategy  of  layered  cyber 
deterrence.  Tune  in  to  hear  from  CSC  Commissioners  and  Industry  leaders  to  discuss  the 
report’s  findings,  educational  aspects,  and  opportunities  to  improve  Cyber-oriented  education. 

FutureCon  Virtual  Eastern  Conference  (Online,  June  30,  2020)  This  virtual  event  features 
thought-provoking  presentations  by  Industry  Security  Leaders,  esteemed  Keynote  Speakers, 
and  a  Panel  Session  discussion  with  experienced  professionals  and  a  talented  team  who  are 
at  the  forefront  of  cutting  edge  strategies  for  Cybersecurity  defense.  100%  off  promo  code: 


CYBERWIRE 


loT  Integrator  Summit:  Securing  Edge  Computing  (Online,  July  14  -  16,  2020)  A  virtual 
summit  to  help  loT  Integrators  learn  more  about  advances  and  updates  in  loT  security  and 
discover  new  methods  for  architecting  loT  solutions  for  your  organization  or  your  clients. 

RSA  Conference  APJ  July  15-17,  2020  -  A  Virtual  Learning  Experience  (Online,  July  15  - 
17,  2020)  The  world’s  leading  cybersecurity  event  is  going  virtual  15-17  July.  Join  your  peers 
and  industry  experts  for  three  days  of  insights.  Watch  over  50  sessions  live  during  Singapore 
business  hours — or  stream  them  later.  Register  today  for  free. 


SELECTED  READING 


Cyber  Attacks,  Threats,  and  Vulnerabilities 

Journalist’s  phone  hacked  by  new  ‘invisible’  technique:  All  he  had  to  do  was  visit  one 

website.  Any  website.  (Record)  Moroccan  journalist  Omar  Radi  investigates  connections 
between  politicians  and  business  people,  as  well... 

NSO  spyware  used  against  Moroccan  journalist  days  after  company  pledged  to  respect 

human  rights  (Amnesty  International)  NSO  Group  contributed  to  a  sustained  campaign  by 
the  government  of  Morocco  to  spy  on  Moroccan  journalist... 

Moroccan  Journalist  Targeted  With  Network  Injection  Attacks  Using  NSO  Group’s 

Tools  (Amnesty  International  In  October  2019  Amnesty  International  published  a  first  report 
on  the  use  of  spyware  produced  by  Israeli... 

Find  MORE  on  our  website. 

Cyber  Trends 

IBM  Security  Study  Finds  Employees  New  to  Working  from  Home  Pose  Security  Risk 

(IBM  News  Room)  IBM  (NYSE:  IBM)  Security  today  released  findings  from  a  study  focused 
on  the  behaviors  and  security  risks... 

The  Post-Pandemic  Enterprise:  What  Will  It  Be  Like?  (Wall  Street  Journal)  Enterprises 
should  embrace  and  scale  the  changes,  from  supply  chain  optimization  to  remote  work,  they... 

US  Businesses  Strengthen  Their  Cyber  Defenses,  but  Blind  Spots  Remain.  Reveals 

Annual  Hiscox  Cyber  Readiness  Report  (PR  Newswire)  Hiscox,  the  international  specialist 
insurer,  revealed  businesses  are  enhancing  levels  of  spending  and... 

Find  MORE  on  our  website. 

Marketplace 

Microsoft  Acquires  loT/OT  Security  Leader  CyberX  to  Enable  Unified  Security  Across 

Converged  IT  and  Industrial  Networks  (Yahoo)  Today,  CyberX  announced  that  it  is  being 
acquired  by  Microsoft. 

With  ransomware  attacks  increasing,  cyber  insurance  now  seen  as  a  necessity,  not  a 


luxury  (Security  Magazine)  Threat  actors  launched  a  cyberattack  against  the  Texas  Office  of 
Court  Administration,  the  IT  provider... 

Air  Force  Space  Accelerator  Will  Nurture  Tech  Startups  Focused  on  Cybersecurity  (Air 

Force  Magazine)  The  Air  Force  Space  Accelerator  Program  has  opened  the  competition  for 
its  latest  cohort  of  tech  start-ups... 

Find  MORE  on  our  website. 

Products,  Services,  and  Solutions 

Centrifuge  Addresses  Growing  loT  Compliance  Standards  (ReFirm  Labs)  The  Spring 
2020  release  of  the  Centrifuge  Platform  introduces  binary  differencing  and  loT  security 
compliance... 

Italy's  Soft  Strategy  and  ShadowDragon  Partner  to  provide  Investigative  training  and 

advanced  investigative  capabilities.  (PR  Newswire)  Soft  Strategy  and  ShadowDragon 
partner  together  to  provide  advanced  investigative  training.  As  the  world... 

Security  Gaining  Attention  On  IBM  i.  But  More  Progress  Needed  (IT  Jungle)  First,  the 
good  news:  IBM  i  shops  are  paying  more  attention  to  security  and  are  making  it  a  priority,... 

Find  MORE  on  our  website. 

Technologies,  Techniques,  and  Standards 

NSA  Updates  Telework  Tech  Guide  for  Agencies  (Meritalk)  The  National  Security  Agency 
(NSA)  updated  its  telework  tech  security  guidance  June  4  with  new  details... 

Does  a  generalization  of  tracking  data  cover  up  our  traces  on  the  internet?  (Help  Net 
Security)  Computer  scientists  of  KIT  and  TU  Dresden  study  how  well  a  generalization  of 
tracking  data  covers  up... 

The  UK’s  contact  tracing  app  fiasco  is  a  master  class  in  mismanagement  (MIT 
Technology  Review)  There  are  advantages  to  being  one  of  the  world’s  largest  single-payer 
health-care  systems.  For  the  UK’s... 

Find  MORE  on  our  website. 

Research  and  Development 

CSIRO's  Data61  develops  voice  detection  technigue  to  prevent  voice  spoofing  attacks 

(ZDNet)  Void  can  detect  the  'liveness'  of  a  voice. 

Legislation,  Policy,  and  Regulation 

Commission  reports  on  2019  European  elections:  fostering  European  debates  and 

securing  free  and  fair  elections  (European  Commission)  Today,  the  European  Commission 
has  published  its  report  on  the  conduct  of  the  2019  elections  to  the  European... 

Unification  Ministry  to  Upgrade  Computer  System  to  Counter  Cyberattacks  from  N. 

Korea  (KBS  World)  South  Korea's  Unification  Ministry  will  reportedly  upgrade  its  computer 


system  to  enhance  security  and... 


China  to  establish  'national  security  agency'  in  Hong  Kong  (China  to  establish  'national 
security  agency'  in  Hong  Kong)  The  agency  for  semi-autonomous  city  will  collect  intelligence 
and  handle  crimes  against  national  security,... 

Find  MORE  on  our  website. 

Litigation,  Investigation,  and  Law  Enforcement 

China  says  espionage  cases  against  Canadians  not  linked  to  Huawei  CFO  (WTVB) 
China  said  on  Monday  the  espionage  cases  against  two  Canadian  citizens  in  the  country  are 
unrelated  to... 

ACT  govt  urged  to  improve  data  security  after  shocker  audit  (iTnews)  Agencies  lacking 
understanding,  awareness. 

Wirecard  Says  Missing  $2  Billion  Probably  Doesn’t  Exist  (Wall  Street  Journal)  The 
announcement  leaves  the  company,  once  considered  Germany’s  pre-eminent  fintech  player, 
fighting  for... 

Find  MORE  on  our  website. 


INDUSTRY  EVENTS 


For  a  complete  running  list  of  events,  please  visit  the  Event  T racker  on  the  CyberWire 
website. 

Upcoming  Events 

WSIS  Forum  2020  (,  June  22  -  September  10,  2020)  The  World  Summit  on  the  Information 
Society  (WSIS)  Forum  2020,  celebrates  15  years  of  providing  a  multi-stakeholder... 

Hardware  Hacking  Virtual  Conference  (Online,  June  24,  2020)  Join  the  ioXt  Alliance  and 
register  now  for  our  upcoming  Summer  Virtual  Conference.  You’ll  hear  the  latest... 

Texas  Cyber  June’qle  Virtual  Summit  (Online,  June  27  -  28,  2020)  The  Texas  Cyber 
June’gle  Virtual  Summit  is  June  27th  and  June  28th,  it  runs  approximately  30  hours  straight,... 

FutureCon  Virtual  Eastern  Conference  (Online,  June  30,  2020)  This  virtual  event  features 
thought-provoking  presentations  by  Industry  Security  Leaders,  esteemed  Keynote... 

CS4CA  World:  Global  Cyber  Security  Event  (Online,  June  30,  2020)  CS4CA  World  will 
take  place  virtually  as  a  unique  large-scale  event  to  keep  the  critical  asset  community... 


SPONSOR  &  SUPPORT 


Grow  your  brand  and  reach  new  customers. 


Grow  your  brand  and  increase  your  customer  base  by  educating  our  audience  about  your 
products,  services,  and  events  by  advertising  on  The  CyberWire.  We’ve  built  trust  with  an 
influential  (and  often  hard  to  reach)  audience  of  CISOs,  CSOs,  and  other  senior  execs  in  the 
security  space,  across  a  wide  array  of  industry  verticals.  Learn  more. 
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IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


To: 


Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov>,  Keith  Morrison 
<Keith.Morrison@cookcountyil.gov>,  Adnan  Memon  (Sheriff) 
<Adnan. Memon@cookcountyil.gov> 

June  23,  2020  6:09:30  AM  CDT 
June  23,  2020  6:09:26  AM  CDT 


Sent: 

Received: 


Krebs  on  Security  reports  Blue  Leaks  has  posted  24  years  of  LEA  and  fusion  center-related  data  as  the  result  of  a 
breach  on  Netsential,  an  internet  services  provider  to  LEAs  and  operational  fusion  centers.  The  data  includes  some 
information  related  to  sensitive  operations  and  a  significant  amount  of  Pll. 

The  Krebs  on  Security  story  can  be  found  here 

Keith  -  do  we  have  any  exposure  from  this  breach  either  directly  from  our  own  infrastructure  or  indirectly  as  the 
result  of  data-sharing  with  other  agencies?  Do  any  of  our  vendors  use  or  have  they  used  Netsential  for  any  of  their 
operations  from  1994  to  present? 


Douglas  MacLean 
Deputy  CIO 

Cook  County  Sheriffs  Office 
3026  S.  California 
South  Campus  Building  1 
Chicago  IL  60608 
312.877.2048  [c] 
773.674.8615  [d] 


IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


To: 

Sent: 

Received: 


Amar  Patel  (Sheriff),  Keith  Morrison,  Adnan  Memon  (Sheriff) 
June  23,  2020  6:09:30  AM  CDT 
June  23,  2020  6:09:26  AM  CDT 


IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


To: 

Sent: 

Received: 


Amar  Patel  (Sheriff),  Keith  Morrison  (Sheriff),  Adnan  Memon  (Sheriff), 
isn@lists.infosecnews.org,  Sheriff  Intel,  Jonathan  Springborn  (Sheriff),  Christopher 
Moore  (Sheriff),  Patrick  Kelly  (Sheriff) 

June  23,  2020  6:09:46  AM  CDT 
June  23,  2020  6:09:48  AM  CDT 


IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


From:  Douglas  Maclean  (Sheriff)  </0=EXCHANGELABS/OU=EXCHANGE  ADMINISTRATIVE 

GROUP 

(FYDIBOHF23SPDLT)/CN=RECIPIENTS/CN=20EA541 1 E8A349589C43587009EDD1  OF 
-DOUGLAS  MAC> 

To:  Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov>,  Keith  Morrison  (Sheriff) 

<Keith.Morrison@cookcountyil.gov>,  Adnan  Memon  (Sheriff) 

<Adnan. Memon@cookcountyil.gov> 

Sent:  June  23,  2020  6:09:46  AM  CDT 

Received:  June  23,  2020  6:09:00  AM  CDT 

Krebs  on  Security  reports  Blue  Leaks  has  posted  24  years  of  LEA  and  fusion  center-related  data  as  the  result  of  a 
breach  on  Netsential,  an  internet  services  provider  to  LEAs  and  operational  fusion  centers.  The  data  includes  some 
information  related  to  sensitive  operations  and  a  significant  amount  of  Pll. 

The  Krebs  on  Security  story  can  be  found  here 

Keith  -  do  we  have  any  exposure  from  this  breach  either  directly  from  our  own  infrastructure  or  indirectly  as  the 
result  of  data-sharing  with  other  agencies?  Do  any  of  our  vendors  use  or  have  they  used  Netsential  for  any  of  their 
operations  from  1994  to  present? 


Douglas  MacLean 
Deputy  CIO 

Cook  County  Sheriffs  Office 
3026  S.  California 
South  Campus  Building  1 
Chicago  IL  60608 
312.877.2048  [c] 
773.674.8615  [d] 


RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


From:  Keith  Morrison  (Sheriff)  </0=EXCHANGELABS/OU=EXCHANGE  ADMINISTRATIVE 

GROUP 

(FYDIBOHF23SPDLT)/CN=RECIPIENTS/CN=D2EBEC5431A14B10A53942341  DBD54F 
4-KEITH  MORRI> 

To:  Douglas  Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov>,  Amar  Patel  (Sheriff) 

<Amar.Patel@cookcountyil.gov>,  Adnan  Memon  (Sheriff) 
<Adnan.Memon@cookcountyil.gov> 

Sent:  June  23,  2020  6:19:51  AM  CDT 

Received:  June  23,  2020  6:19:00  AM  CDT 

Deputy  CIO  Maclean, 


Thanks, 


Morrison 


From:  Douglas  Maclean  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:10  AM 

To:  Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov>;  Keith  Morrison  (Sheriff) 
<Keith.Morrison@cookcountyil.gov>;  Adnan  Memon  (Sheriff)  <Adnan. Memon@cookcountyil.gov> 

Subject:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Krebs  on  Security  reports  Blue  Leaks  has  posted  24  years  of  LEA  and  fusion  center-related  data  as  the  result  of  a 
breach  on  Netsential,  an  internet  services  provider  to  LEAs  and  operational  fusion  centers.  The  data  includes  some 
information  related  to  sensitive  operations  and  a  significant  amount  of  Pll. 

The  Krebs  on  Security  story  can  be  found  here 

Keith  -  do  we  have  any  exposure  from  this  breach  either  directly  from  our  own  infrastructure  or  indirectly  as  the 
result  of  data-sharing  with  other  agencies?  Do  any  of  our  vendors  use  or  have  they  used  Netsential  for  any  of  their 
operations  from  1994  to  present? 


Douglas  MacLean 
Deputy  CIO 

Cook  County  Sheriffs  Office 
3026  S.  California 
South  Campus  Building  1 
Chicago  IL  60608 
312.877.2048  [c] 
773.674.8615  [d] 


FW:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


From:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

To:  Christopher  Moore  (Sheriff)  <Christopher.Moore@cookcountyil.gov> 

Sent:  June  23,  2020  6:20:39  AM  CDT 

Received:  June  23,  2020  6:20:40  AM  CDT 

No  Action  Needed 

From:  Keith  Morrison  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:20  AM 

To:  Douglas  Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov>;  Amar  Patel  (Sheriff) 
<Amar.Patel@cookcountyil.gov>;  Adnan  Memon  (Sheriff)  <Adnan. Memon@cookcountyil.gov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Deputy  CIO  Maclean, 


Thanks, 

Morrison 


From:  Douglas  Maclean  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:10  AM 

To:  Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov>:  Keith  Morrison  (Sheriff) 
<Keith.Morrison@cookcountyil.gov>;  Adnan  Memon  (Sheriff)  <Adnan.Memon@cookcountyil.gov> 

Subject:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Krebs  on  Security  reports  Blue  Leaks  has  posted  24  years  of  LEA  and  fusion  center-related  data  as  the  result  of  a 
breach  on  Netsential,  an  internet  services  provider  to  LEAs  and  operational  fusion  centers.  The  data  includes  some 
information  related  to  sensitive  operations  and  a  significant  amount  of  Pll. 

The  Krebs  on  Security  story  can  be  found  here 

Keith  -  do  we  have  any  exposure  from  this  breach  either  directly  from  our  own  infrastructure  or  indirectly  as  the 
result  of  data-sharing  with  other  agencies?  Do  any  of  our  vendors  use  or  have  they  used  Netsential  for  any  of  their 
operations  from  1994  to  present? 


Douglas  MacLean 
Deputy  CIO 

Cook  County  Sheriffs  Office 
3026  S.  California 
South  Campus  Building  1 
Chicago  IL  60608 
312.877.2048  [c] 
773.674.8615  [d] 


FW:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


From: 


Keith  Morrison  (Sheriff)  </0=EXCHANGELABS/OU=EXCHANGE  ADMINISTRATIVE 
GROUP 

(FYDIBOHF23SPDLT)/CN=RECIPIENTS/CN=D2EBEC5431A14B10A53942341  DBD54F 
4-KEITH  MORRI> 


To: 

Sent: 

Received: 


Christopher  Moore  (Sheriff)  <Christopher.Moore@cookcountyil.gov> 
June  23,  2020  6:20:39  AM  CDT 
June  23,  2020  6:20:00  AM  CDT 


No  Action  Needed 

From:  Keith  Morrison  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:20  AM 

To:  Douglas  Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov>;  Amar  Patel  (Sheriff) 
<Amar.Patel@cookcountyil.gov>;  Adnan  Memon  (Sheriff)  <Adnan. Memon@cookcountyil.gov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Deputy  CIO  Maclean, 


Thanks, 


Morrison 


From:  Douglas  Maclean  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:10  AM 

To:  Amar  Patel  (Sheriff)  <Amar. Patel @cookcountyil.gov>;  Keith  Morrison  (Sheriff) 

<Keith.  Morrison@cookcountyil.gov>;  Adnan  Memon  (Sheriff)  <Adnan.Memon(5)cookcountvil.gov> 

Subject:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Krebs  on  Security  reports  Blue  Leaks  has  posted  24  years  of  LEA  and  fusion  center-related  data  as  the  result  of  a 
breach  on  Netsential,  an  internet  services  provider  to  LEAs  and  operational  fusion  centers.  The  data  includes  some 
information  related  to  sensitive  operations  and  a  significant  amount  of  Pll. 

The  Krebs  on  Security  story  can  be  found  here 

Keith  -  do  we  have  any  exposure  from  this  breach  either  directly  from  our  own  infrastructure  or  indirectly  as  the 
result  of  data-sharing  with  other  agencies?  Do  any  of  our  vendors  use  or  have  they  used  Netsential  for  any  of  their 
operations  from  1994  to  present? 


Douglas  MacLean 
Deputy  CIO 

Cook  County  Sheriffs  Office 
3026  S.  California 
South  Campus  Building  1 
Chicago  IL  60608 
312.877.2048  [c] 
773.674.8615  [d] 


FW:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


To: 

Cc: 

Sent: 

Received: 


Christopher  Moore  (Sheriff),  Douglas  Maclean  (Sheriff),  Amar  Patel  (Sheriff),  Adnan 
Memon  (Sheriff),  Donna  Fitzpatrick  (Sheriff),  Gregory.Wing@ic.fbi.gov, 

Michael. Tomasiello  (Chicago  Police),  CCSO  Intel  (Sheriff),  Kevin  O'Donnell  (Sheriff) 
Adnan  Memon  (Sheriff),  Douglas  Maclean  (Sheriff),  Amar  Patel  (Sheriff) 

June  23,  2020  6:20:39  AM  CDT 
June  23,  2020  6:20:00  AM  CDT 


RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


To: 

Cc: 

Sent: 

Received: 


Keith  Morrison  (Sheriff),  Amar  Patel  (Sheriff),  Adnan  Memon  (Sheriff),  Patrick  Kelly 
(Sheriff),  Christopher  Moore  (Sheriff),  Sheriff  Intel,  Jonathan  Springborn  (Sheriff), 
Michael  Aliperti,  Ben  Spear 
Adnan  Memon  (Sheriff),  Douglas  Maclean  (Sheriff) 

June  23,  2020  6:26:1 1  AM  CDT 
June  23,  2020  6:26:13  AM  CDT 


RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


From: 


Douglas  Maclean  (Sheriff)  </0=EXCHANGELABS/OU=EXCHANGE  ADMINISTRATIVE 
GROUP 

(FYDIBOHF23SPDLT)/CN=RECIPIENTS/CN=20EA541 1 E8A349589C43587009EDD1  OF 
-DOUGLAS  MAC> 

Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov>,  Amar  Patel  (Sheriff) 
<Amar.Patel@cookcountyil.gov>,  Adnan  Memon  (Sheriff) 

<Adnan. Memon@cookcountyil.gov> 

June  23,  2020  6:26:1 1  AM  CDT 
June  23,  2020  6:26:00  AM  CDT 


To: 


Sent: 
Received: 
Keith  - 


Doug 


From:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

Sent:  Tuesday,  June  23,  2020  6:20  AM 

To:  Douglas  Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov>;  Amar  Patel  (Sheriff) 
<Amar.Patel@cookcountyil.gov>;  Adnan  Memon  (Sheriff)  <Adnan.Memon@cookcountyil.gov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Deputy  CIO  Maclean, 


Thanks, 


Morrison 


From:  Douglas  Maclean  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:10  AM 

To:  Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov>;  Keith  Morrison  (Sheriff) 
<Keith.Morrison@cookcountyil.gov>;  Adnan  Memon  (Sheriff)  <Adnan. Memon@cookcountyil.gov> 

Subject:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Krebs  on  Security  reports  Blue  Leaks  has  posted  24  years  of  LEA  and  fusion  center-related  data  as  the  result  of  a 
breach  on  Netsential,  an  internet  services  provider  to  LEAs  and  operational  fusion  centers.  The  data  includes  some 
information  related  to  sensitive  operations  and  a  significant  amount  of  Pll. 

The  Krebs  on  Security  story  can  be  found  here 

Keith  -  do  we  have  any  exposure  from  this  breach  either  directly  from  our  own  infrastructure  or  indirectly  as  the 
result  of  data-sharing  with  other  agencies?  Do  any  of  our  vendors  use  or  have  they  used  Netsential  for  any  of  their 
operations  from  1994  to  present? 


Douglas  MacLean 
Deputy  CIO 


Cook  County  Sheriffs  Office 
3026  S.  California 
South  Campus  Building  1 
Chicago  IL  60608 
312.877.2048  [c] 
773.674.8615  [d] 


lACP's  The  Lead:  US  Supreme  Court  Will  Not  Revisit  Challenge  To  Qualified 
Immunity  For  Police. 

From:  The  IACP  <TheLead@iacp. bulletinmedia.com> 

To:  jennifer.warren@cookcountyil.gov,  Jennifer  Warren  (Sheriff) 

Jennifer.  warren@cookcountyil.gov> 

Sent:  June  23,  2020  6:43:06  AM  CDT 

Received:  June  23,  2020  6:43:21  AM  CDT 


External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 

If  you  are  unable  to  see  the  message  or  images  below,  click  here  to  view 


POLICING  &  POLICY 


US  Supreme  Court  Will  Not  Revisit  Challenge  To  Qualified 
Immunity  For  Police 

<\BC  News  ^^B(6/22,  Dwyer)  reports,  "The  U.S.  Supreme  Court  on 
Monday  officially  took  a  pass  on  revisiting  its  50-year-old  doctrine  of 
qualified  immunity'  for  law  enforcement  officers,  despite  intense 
national  outcry  over  police  misconduct  and  legal  protections  that  shield 
:ops  from  liability.  'The  Supreme  Court  has  made  clear  that  they  are  not 
arepared  to  reconsider  qualified  immunity  at  this  moment,'  said  Joanna 
Schwartz,  an  expert  on  the  doctrine  at  UCLA  School  of  Law."  ABC  News 
adds,  "While  the  Civil  Rights  Act  of  1871  gives  Americans  the 
unambiguous  ability  to  sue  public  officials  over  civil  rights  violations,  the 
Supreme  Court  subsequently  limited  liability  to  only  those  rights  that 
have  become  'clearly  established  law.'" 

Newsday  (NY)  (6/22,  Brune)  reports  that  qualified  immunity  "shields  police  from  being  sued  for  money  damages  in 
federal  court  for  constitutional  violations  such  as  excessive  force  unless  the  officers  broke  any  'clearly  established'  law  -  a  high 
bar  for  plaintiffs  to  overcome."  Newsday  adds  that  police  groups  argue  that  ending  qualified  immunity  "would  have  a  chilling 
effect  on  police  work,  make  them  hesitant  to  act  when  they  should  be  decisive  in  dicey  situations,  or  lead  to  retirements  and  a 
smaller  pool  of  applicants  for  police  jobs.  'Qualified  immunity  is  a  foundational  protection  for  the  policing  profession  and  any 
modification  to  this  legal  standard  will  have  a  devastating  impact  on  the  police's  ability  to  fulfill  its  public  safety  mission,'  the 
International  Association  of  Chiefs  of  Police  said  in  a  statement." 


Senate  Democrats  Threaten  To  Block  GOP  Police  Reform  Bill 

Politico  (6/22,  Everett,  Levine)  reports  Senate  Democrats  are  "strongly  signaling  they  will  filibuster  Republicans'  police 
reform  bill  later  this  week  absent  more  concessions"  from  Senate  Majority  Leader  McConnell,  who  "set  the  Senate  on  a  path  to 
consider  the  legislation  on  Wednesday."  Sen.  Jon  Tester  (D-MT)  said,  "If  nothing  changes,  I'm  voting  no.  I  need  some  assurances 
that  we're  going  to  vote  on  amendments  that  will  fix  this  bill.  And  it  needs  a  lot  of  fixing."  Senate  Minority  Leader  Schumer 
called  the  GOP  bill  "deeply  and  fundamentally  flawed." 

Reuters  Analysis:  Neither  Senate  Nor  House  Police  Reform  Bill  Likely  To  Become  Law.  Reuters  (6/22, 

Morgan)  reports  that  the  Senate  and  the  House  "will  vote  this  week  on  separate  bills  aimed  at  addressing  police 
misconduct. ..but  neither  measure  is  likely  to  become  law."  The  Senate  "is  expected  to  hold  a  procedural  vote  on  a  Republican 
bill  by  Wednesday,  while  the  House  is  due  to  vote  on  more  sweeping  Democratic  legislation  on  Thursday."  However,  Reuters 
says,  "neither  measure,  as  written,  appears  to  have  enough  bipartisan  support  to  win  approval  from  both  chambers  and  be 
signed  into  law." 

Studies  Find  Recreational  Marijuana  Laws  May  Boost  Traffic  Deaths 

The  AP  (6/22,  Tanner)  reports,  "Laws  legalizing  recreational  marijuana  may  lead  to  more  traffic  deaths,  two  new  studies 
suggest,  although  questions  remain  about  how  they  might  influence  driving  habits."  According  to  the  AP,  "Previous  research 
has  had  mixed  results  and  the  new  studies,  published  Monday  in  JAMA  Internal  Medicine,  can't  prove  that  the  traffic  death 
increases  they  found  were  caused  by  marijuana  use."  The  AP  adds,  "One  study  found  an  excess  75  traffic  deaths  per  year  after 
retail  sales  began  in  Colorado  in  January  2014,  compared  with  states  without  similar  laws,"  but  "it  found  no  similar  change  in 
Washington  state."  The  other  study  "looked  at  those  states  plus  two  others  that  allow  recreational  pot  sales,  Oregon  and 
Alaska.  If  every  state  legalized  recreational  marijuana  sales,  an  extra  6,800  people  would  die  each  year  in  traffic  accidents,  the 
researchers  calculated." 

Pandemic  Has  Increased  New  York  City  Criminal  Court  Backlog  To  More  Than  39K  Cases 

The  New  York  Times  (6/22,  Al,  Feuer,  Hong,  Weiser,  Ransom)  has  a  2,400-word  report  on  what  it  calls  New  York  City's 
"legal  limbo,"  where  "the  backlog  of  pending  cases  in  the  city's  criminal  courts  has  risen  by  nearly  a  third"  to  39,200  due  to  the 
coronavirus  pandemic.  The  Times  says  "hundreds  of  jury  trials  in  the  city  have  been  put  on  hold  indefinitely,"  and 
"arraignments,  pleas  and  evidentiary  hearings  are  being  held  by  video,  with  little  public  scrutiny." 

Massachusetts  Governor  Seeks  Training  Bonuses  For  Police  Officers 

Boston  (6/22,  Gavin)  reports,  "Police  officers  in  Massachusetts  could  receive  one-time  bonuses  of  up  to  $5,000  should 
they  take  on  additional  training  under  a  bill  filed  last  week  by  Gov.  Charlie  Baker  centered  on  creating  a  police  certification 
system."  According  to  Boston,  "The  vision  is  to  incentivize  officers  to  go  beyond  the  necessary  minimum  training  laid  out  in  the 
sweeping  proposal,  which  comes  amid  the  nationwide  movement  to  reduce  funding  for  law  enforcement,  and  instead  funnel 
resources  into  other  initiatives  such  as  anti-violence  and  public  health  programs."  The  bill,  "which  seeks  to  establish  a  system  to 
uniformly  certify,  and  de-certify,  police  officers,"  would  "provide  financial  opportunity  to  officers  to  advance  their  training  in 
key  areas,  including  first  aid,  de-escalation  tactics,  and  narcotics  training." 

San  Diego,  California  Ballot  Measure  Would  Reform  Police  Oversight,  Accountability 

The  San  Diego  Union-Tribune  M  (6/22,  Garrick)  reports  San  Diego  may  "take  a  key  step  Tuesday  toward  more  rigorous  police 
oversight,  transparency  and  accountability."  The  San  Diego  City  Council  "is  scheduled  to  evaluate  a  proposed  November  ballot 
measure  that  would  create  a  police  review  board  with  the  power  to  launch  independent  misconduct  investigations  and 
subpoena  witnesses.  While  the  proposal  has  been  in  the  works  for  several  years,  it  gained  momentum  in  the  wake  of  recent 
local  and  national  police  protests  that  have  sparked  calls  for  fundamental  law  enforcement  reforms."  The  city  "completed 
negotiations  May  21  with  the  labor  union  representing  police  officers  on  the  proposed  ballot  measure,  which  would  let  officers 
appeal  declarations  by  the  commission  that  they  are  guilty  of  misconduct." 


Join  the  IACP  on  June  24,  2020,  at  1:00  p.m.  EST  for  Part  2  and  July  16,  2020,  at  1:00  p.m.  EST  for  Part  3  of 
Mindfulness  Strategies  for  Law  Enforcement  webinar  series.  This  webinar  is  part  of  the  U.S.  Department  of 
Justice,  Bureau  of  Justice  Assistance's  National  Officer  Safety  Initiatives  Program  and  will  be  hosted  by  Mindful 
Junkie  Founder,  Gina  White.  Police  officers  across  every  rank,  dispatchers,  victim  services  personnel,  crime  scene 
personnel,  other  law  enforcement  personnel  and  family  members  are  encouraged  to  attend  these  30-minute 
interactive  mindfulness  sessions. 
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CRIME  &  DRUGS 


Swedish  Rape  Conviction  Rates  Rise  75%  After  Change  In  Law 

Reuters  (6/22,  Batha)  reports,  "Rape  conviction  rates  in  Sweden  have  risen  75%  in  two  years  following  a  major  change  in 
the  law,  spurring  calls  on  Monday  for  other  countries  to  revamp  their  legislation."  Reuters  adds,  "Sweden  changed  the  legal 
definition  of  rape  in  2018  to  sex  without  consent.  Unlike  in  many  countries,  prosecutors  do  not  have  to  prove  the  use  or  threat 
of  violence  or  coercion.  The  National  Council  on  Crime  Prevention  (Bra)  said  the  rise  in  convictions  -  up  from  190  in  2017  to  333 
in  2019  -  showed  the  change  had  had  a  greater  impact  than  expected."  According  to  Reuters,  "Britain,  Belgium,  Canada, 

Cyprus,  Germany,  Greece,  Iceland,  Ireland  and  Luxembourg  already  define  rape  as  sex  without  consent,  while  Denmark, 

Finland,  Spain  and  Portugal  have  promised  similar  reforms." 

New  York  City  Raid  Leads  To  Drug  Seizures,  Two  Arrests 

The  New  York  Post  (6/22,  Rosenberg)  reports  a  recent  raid  of  a  suspected  pill  mill  in  New  York  City  led  to  the  seizure  of 
"approximately  1.2  kilograms  of  heroin,  34  grams  of  fentanyl  and  2.3  kilograms  of  methamphetamine."  Arrested  in  connection 
with  the  raid  were  Jeison  Lebron  and  Alfredo  Goris,  who  face  "charges  of  criminal  possession  of  a  controlled  substance  and 
criminally  using  drug  paraphernalia."  The  arrests  were  the  result  of  joint  operation  conducted  by  "the  city's  Special  Narcotics 
Prosecutor,"  the  City  of  New  York  Police  Department,  and  the  DEA. 

UK  Drinkers  Barricade  Themselves  In  Pub  During  Illegal  Lockdown  Lock-In 

The  Independent  (UK)  (6/22,  Gregory)  reports,  "Drinkers  at  an  illegal  lockdown-defying  lock-in  have  barricaded 
themselves  in  a  pub  after  police  officers  arrived  to  break  up  the  session,  according  to  police."  According  to  the  Independent, 
"Merseyside  Police  officers  were  pelted  with  beer  and  other  items  as  revellers  took  up  their  fortified  position  at  the  Britannia 
Hotel  pub  in  Liverpool,  the  force  said.  There  were  reportedly  more  than  100  people  gathered  at  the  Vauxhall  pub  at  around 
midnight  on  Sunday,  playing  loud  music  and  disturbing  residents  nearby,  although  only  'a  number  of  people'  were  said  to  take 
part  in  the  blockade."  The  Independent  adds,  "Seven  men  and  one  woman,  aged  between  21  and  33,  were  arrested  for  violent 
disorder  and  drugs  offences.  Pubs  have  been  closed  by  law  for  the  last  three  months  to  fight  the  spread  of  coronavirus,  with 
Boris  Johnson  expected  to  allow  them  to  re-open  on  4  July,  albeit  with  a  range  of  new  measures  in  place  to  protect  customers." 

TECHNOLOGY 


"Blueleaks"  Hackers  Release  "Hundreds  Of  Thousands"  Of  Private  Records  On  Officers 

The  Blaze  (6/22,  Taylor)  reports  hackers  have  "leaked  highly  sensitive  police  files  from  over  200  police  departments  across 
the  country."  Activist  group  DDoSecrets  "published  what  the  outlet  calls  'hundreds  of  gigabytes'  worth  of  potentially  sensitive 
files'  from  police  departments  across  the  US."  The  group  has  "called  the  information  dump  'BlueLeaks.'"  The  group  "compiled 
the  records,  disseminating  them  into  a  searchable  database  that  can  pull  up  private  information  from  a  police  badge  number." 
Many  of  the  files  include  "information  such  as  memos,  emails,  and  officers'  personal  information".  The  group  "shared 
information  on  Twitter  regarding  the  data  dump." 


GLOBAL  SECURITY 


NYTimes  Analysis:  Antifa  Rumors  Show  Ways  Information  Spreads  Locally 

The  New  York  Times  (6/22,  Alba,  Decker)  examines  how  in  recent  weeks,  "residents  in  at  least  41  U.S.  cities  and  towns 
became  alarmed  by  rumors  that  the  loose  collective  of  anti-fascist  activists  known  as  antifa  was  headed  to  their  area,  according 
to  an  analysis  by  The  New  York  Times.  In  many  cases,  they  contacted  their  local  law  enforcement  for  help.  In  each  case,  it  was 
for  a  threat  that  never  appeared."  On  the  local  level,  the  analysis  found  that  "the  source  of  the  false  information  has  usually 
been  more  subtle,  and  shows  the  complexity  of  stunting  misinformation  online.  The  bad  information  often  first  appears  in  a 
Twitter  or  Facebook  post,  or  a  YouTube  video  there.  It  is  then  shared  on  online  spaces  like  local  Facebook  groups,  the 
neighborhood  social  networking  app  Nextdoor  and  community  texting  networks,"  which  "can  fall  under  the  radar  of  the  tech 
companies  and  online  fact  checkers." 

Black  Lives  Matter  Protests  Spread  To  White,  Rural  Areas.  The  Wall  Street  Journal  ^H(6/22,  Carlton,  Subscription 
Publication)  reports  that  the  protests  for  racial  justice  have  quickly  spread  from  big  cities  to  small,  rural  towns  that  are 
predominantly  white. 
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US  Supreme  Court  Will  Not  Revisit  Challenge  To  Qualified 
Immunity  For  Police 

<\BC  News  ^^B(6/22,  Dwyer)  reports,  "The  U.S.  Supreme  Court  on 
Monday  officially  took  a  pass  on  revisiting  its  50-year-old  doctrine  of 
qualified  immunity'  for  law  enforcement  officers,  despite  intense 
national  outcry  over  police  misconduct  and  legal  protections  that  shield 
:ops  from  liability.  'The  Supreme  Court  has  made  clear  that  they  are  not 
arepared  to  reconsider  qualified  immunity  at  this  moment,'  said  Joanna 
Schwartz,  an  expert  on  the  doctrine  at  UCLA  School  of  Law."  ABC  News 
adds,  "While  the  Civil  Rights  Act  of  1871  gives  Americans  the 
unambiguous  ability  to  sue  public  officials  over  civil  rights  violations,  the 
Supreme  Court  subsequently  limited  liability  to  only  those  rights  that 
have  become  'clearly  established  law.'" 

Newsday  (NY)  (6/22,  Brune)  reports  that  qualified  immunity  "shields  police  from  being  sued  for  money  damages  in 
federal  court  for  constitutional  violations  such  as  excessive  force  unless  the  officers  broke  any  'clearly  established'  law  -  a  high 
bar  for  plaintiffs  to  overcome."  Newsday  adds  that  police  groups  argue  that  ending  qualified  immunity  "would  have  a  chilling 
effect  on  police  work,  make  them  hesitant  to  act  when  they  should  be  decisive  in  dicey  situations,  or  lead  to  retirements  and  a 
smaller  pool  of  applicants  for  police  jobs.  'Qualified  immunity  is  a  foundational  protection  for  the  policing  profession  and  any 
modification  to  this  legal  standard  will  have  a  devastating  impact  on  the  police's  ability  to  fulfill  its  public  safety  mission,'  the 
International  Association  of  Chiefs  of  Police  said  in  a  statement." 


Senate  Democrats  Threaten  To  Block  GOP  Police  Reform  Bill 

Politico  (6/22,  Everett,  Levine)  reports  Senate  Democrats  are  "strongly  signaling  they  will  filibuster  Republicans'  police 
reform  bill  later  this  week  absent  more  concessions"  from  Senate  Majority  Leader  McConnell,  who  "set  the  Senate  on  a  path  to 
consider  the  legislation  on  Wednesday."  Sen.  Jon  Tester  (D-MT)  said,  "If  nothing  changes,  I'm  voting  no.  I  need  some  assurances 
that  we're  going  to  vote  on  amendments  that  will  fix  this  bill.  And  it  needs  a  lot  of  fixing."  Senate  Minority  Leader  Schumer 
called  the  GOP  bill  "deeply  and  fundamentally  flawed." 

Reuters  Analysis:  Neither  Senate  Nor  House  Police  Reform  Bill  Likely  To  Become  Law.  Reuters  (6/22, 

Morgan)  reports  that  the  Senate  and  the  House  "will  vote  this  week  on  separate  bills  aimed  at  addressing  police 
misconduct. ..but  neither  measure  is  likely  to  become  law."  The  Senate  "is  expected  to  hold  a  procedural  vote  on  a  Republican 
bill  by  Wednesday,  while  the  House  is  due  to  vote  on  more  sweeping  Democratic  legislation  on  Thursday."  However,  Reuters 
says,  "neither  measure,  as  written,  appears  to  have  enough  bipartisan  support  to  win  approval  from  both  chambers  and  be 
signed  into  law." 

Studies  Find  Recreational  Marijuana  Laws  May  Boost  Traffic  Deaths 

The  AP  (6/22,  Tanner)  reports,  "Laws  legalizing  recreational  marijuana  may  lead  to  more  traffic  deaths,  two  new  studies 
suggest,  although  questions  remain  about  how  they  might  influence  driving  habits."  According  to  the  AP,  "Previous  research 
has  had  mixed  results  and  the  new  studies,  published  Monday  in  JAMA  Internal  Medicine,  can't  prove  that  the  traffic  death 
increases  they  found  were  caused  by  marijuana  use."  The  AP  adds,  "One  study  found  an  excess  75  traffic  deaths  per  year  after 
retail  sales  began  in  Colorado  in  January  2014,  compared  with  states  without  similar  laws,"  but  "it  found  no  similar  change  in 
Washington  state."  The  other  study  "looked  at  those  states  plus  two  others  that  allow  recreational  pot  sales,  Oregon  and 
Alaska.  If  every  state  legalized  recreational  marijuana  sales,  an  extra  6,800  people  would  die  each  year  in  traffic  accidents,  the 
researchers  calculated." 

Pandemic  Has  Increased  New  York  City  Criminal  Court  Backlog  To  More  Than  39K  Cases 

The  New  York  Times  (6/22,  Al,  Feuer,  Hong,  Weiser,  Ransom)  has  a  2,400-word  report  on  what  it  calls  New  York  City's 
"legal  limbo,"  where  "the  backlog  of  pending  cases  in  the  city's  criminal  courts  has  risen  by  nearly  a  third"  to  39,200  due  to  the 
coronavirus  pandemic.  The  Times  says  "hundreds  of  jury  trials  in  the  city  have  been  put  on  hold  indefinitely,"  and 
"arraignments,  pleas  and  evidentiary  hearings  are  being  held  by  video,  with  little  public  scrutiny." 

Massachusetts  Governor  Seeks  Training  Bonuses  For  Police  Officers 

Boston  (6/22,  Gavin)  reports,  "Police  officers  in  Massachusetts  could  receive  one-time  bonuses  of  up  to  $5,000  should 
they  take  on  additional  training  under  a  bill  filed  last  week  by  Gov.  Charlie  Baker  centered  on  creating  a  police  certification 
system."  According  to  Boston,  "The  vision  is  to  incentivize  officers  to  go  beyond  the  necessary  minimum  training  laid  out  in  the 
sweeping  proposal,  which  comes  amid  the  nationwide  movement  to  reduce  funding  for  law  enforcement,  and  instead  funnel 
resources  into  other  initiatives  such  as  anti-violence  and  public  health  programs."  The  bill,  "which  seeks  to  establish  a  system  to 
uniformly  certify,  and  de-certify,  police  officers,"  would  "provide  financial  opportunity  to  officers  to  advance  their  training  in 
key  areas,  including  first  aid,  de-escalation  tactics,  and  narcotics  training." 

San  Diego,  California  Ballot  Measure  Would  Reform  Police  Oversight,  Accountability 

The  San  Diego  Union-Tribune  M  (6/22,  Garrick)  reports  San  Diego  may  "take  a  key  step  Tuesday  toward  more  rigorous  police 
oversight,  transparency  and  accountability."  The  San  Diego  City  Council  "is  scheduled  to  evaluate  a  proposed  November  ballot 
measure  that  would  create  a  police  review  board  with  the  power  to  launch  independent  misconduct  investigations  and 
subpoena  witnesses.  While  the  proposal  has  been  in  the  works  for  several  years,  it  gained  momentum  in  the  wake  of  recent 
local  and  national  police  protests  that  have  sparked  calls  for  fundamental  law  enforcement  reforms."  The  city  "completed 
negotiations  May  21  with  the  labor  union  representing  police  officers  on  the  proposed  ballot  measure,  which  would  let  officers 
appeal  declarations  by  the  commission  that  they  are  guilty  of  misconduct." 
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Mindfulness  Strategies  for  Law  Enforcement  webinar  series.  This  webinar  is  part  of  the  U.S.  Department  of 
Justice,  Bureau  of  Justice  Assistance's  National  Officer  Safety  Initiatives  Program  and  will  be  hosted  by  Mindful 
Junkie  Founder,  Gina  White.  Police  officers  across  every  rank,  dispatchers,  victim  services  personnel,  crime  scene 
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interactive  mindfulness  sessions. 
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Swedish  Rape  Conviction  Rates  Rise  75%  After  Change  In  Law 

Reuters  (6/22,  Batha)  reports,  "Rape  conviction  rates  in  Sweden  have  risen  75%  in  two  years  following  a  major  change  in 
the  law,  spurring  calls  on  Monday  for  other  countries  to  revamp  their  legislation."  Reuters  adds,  "Sweden  changed  the  legal 
definition  of  rape  in  2018  to  sex  without  consent.  Unlike  in  many  countries,  prosecutors  do  not  have  to  prove  the  use  or  threat 
of  violence  or  coercion.  The  National  Council  on  Crime  Prevention  (Bra)  said  the  rise  in  convictions  -  up  from  190  in  2017  to  333 
in  2019  -  showed  the  change  had  had  a  greater  impact  than  expected."  According  to  Reuters,  "Britain,  Belgium,  Canada, 

Cyprus,  Germany,  Greece,  Iceland,  Ireland  and  Luxembourg  already  define  rape  as  sex  without  consent,  while  Denmark, 

Finland,  Spain  and  Portugal  have  promised  similar  reforms." 

New  York  City  Raid  Leads  To  Drug  Seizures,  Two  Arrests 

The  New  York  Post  (6/22,  Rosenberg)  reports  a  recent  raid  of  a  suspected  pill  mill  in  New  York  City  led  to  the  seizure  of 
"approximately  1.2  kilograms  of  heroin,  34  grams  of  fentanyl  and  2.3  kilograms  of  methamphetamine."  Arrested  in  connection 
with  the  raid  were  Jeison  Lebron  and  Alfredo  Goris,  who  face  "charges  of  criminal  possession  of  a  controlled  substance  and 
criminally  using  drug  paraphernalia."  The  arrests  were  the  result  of  joint  operation  conducted  by  "the  city's  Special  Narcotics 
Prosecutor,"  the  City  of  New  York  Police  Department,  and  the  DEA. 

UK  Drinkers  Barricade  Themselves  In  Pub  During  Illegal  Lockdown  Lock-In 

The  Independent  (UK)  (6/22,  Gregory)  reports,  "Drinkers  at  an  illegal  lockdown-defying  lock-in  have  barricaded 
themselves  in  a  pub  after  police  officers  arrived  to  break  up  the  session,  according  to  police."  According  to  the  Independent, 
"Merseyside  Police  officers  were  pelted  with  beer  and  other  items  as  revellers  took  up  their  fortified  position  at  the  Britannia 
Hotel  pub  in  Liverpool,  the  force  said.  There  were  reportedly  more  than  100  people  gathered  at  the  Vauxhall  pub  at  around 
midnight  on  Sunday,  playing  loud  music  and  disturbing  residents  nearby,  although  only  'a  number  of  people'  were  said  to  take 
part  in  the  blockade."  The  Independent  adds,  "Seven  men  and  one  woman,  aged  between  21  and  33,  were  arrested  for  violent 
disorder  and  drugs  offences.  Pubs  have  been  closed  by  law  for  the  last  three  months  to  fight  the  spread  of  coronavirus,  with 
Boris  Johnson  expected  to  allow  them  to  re-open  on  4  July,  albeit  with  a  range  of  new  measures  in  place  to  protect  customers." 

TECHNOLOGY 


"Blueleaks"  Hackers  Release  "Hundreds  Of  Thousands"  Of  Private  Records  On  Officers 

The  Blaze  (6/22,  Taylor)  reports  hackers  have  "leaked  highly  sensitive  police  files  from  over  200  police  departments  across 
the  country."  Activist  group  DDoSecrets  "published  what  the  outlet  calls  'hundreds  of  gigabytes'  worth  of  potentially  sensitive 
files'  from  police  departments  across  the  US."  The  group  has  "called  the  information  dump  'BlueLeaks.'"  The  group  "compiled 
the  records,  disseminating  them  into  a  searchable  database  that  can  pull  up  private  information  from  a  police  badge  number." 
Many  of  the  files  include  "information  such  as  memos,  emails,  and  officers'  personal  information".  The  group  "shared 
information  on  Twitter  regarding  the  data  dump." 


GLOBAL  SECURITY 


NYTimes  Analysis:  Antifa  Rumors  Show  Ways  Information  Spreads  Locally 

The  New  York  Times  (6/22,  Alba,  Decker)  examines  how  in  recent  weeks,  "residents  in  at  least  41  U.S.  cities  and  towns 
became  alarmed  by  rumors  that  the  loose  collective  of  anti-fascist  activists  known  as  antifa  was  headed  to  their  area,  according 
to  an  analysis  by  The  New  York  Times.  In  many  cases,  they  contacted  their  local  law  enforcement  for  help.  In  each  case,  it  was 
for  a  threat  that  never  appeared."  On  the  local  level,  the  analysis  found  that  "the  source  of  the  false  information  has  usually 
been  more  subtle,  and  shows  the  complexity  of  stunting  misinformation  online.  The  bad  information  often  first  appears  in  a 
Twitter  or  Facebook  post,  or  a  YouTube  video  there.  It  is  then  shared  on  online  spaces  like  local  Facebook  groups,  the 
neighborhood  social  networking  app  Nextdoor  and  community  texting  networks,"  which  "can  fall  under  the  radar  of  the  tech 
companies  and  online  fact  checkers." 

Black  Lives  Matter  Protests  Spread  To  White,  Rural  Areas.  The  Wall  Street  Journal  ^H(6/22,  Carlton,  Subscription 
Publication)  reports  that  the  protests  for  racial  justice  have  quickly  spread  from  big  cities  to  small,  rural  towns  that  are 
predominantly  white. 
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•  Libyan  Refugee  Arrested  In  UK  Terrorist  Attack  That  Left  Three  Dead 
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POLICING  &  POLICY 


US  Supreme  Court  Will  Not  Revisit  Challenge  To  Qualified 
Immunity  For  Police 

<\BC  News  ^^B(6/22,  Dwyer)  reports,  "The  U.S.  Supreme  Court  on 
Monday  officially  took  a  pass  on  revisiting  its  50-year-old  doctrine  of 
qualified  immunity'  for  law  enforcement  officers,  despite  intense 
national  outcry  over  police  misconduct  and  legal  protections  that  shield 
:ops  from  liability.  'The  Supreme  Court  has  made  clear  that  they  are  not 
arepared  to  reconsider  qualified  immunity  at  this  moment,'  said  Joanna 
Schwartz,  an  expert  on  the  doctrine  at  UCLA  School  of  Law."  ABC  News 
adds,  "While  the  Civil  Rights  Act  of  1871  gives  Americans  the 
unambiguous  ability  to  sue  public  officials  over  civil  rights  violations,  the 
Supreme  Court  subsequently  limited  liability  to  only  those  rights  that 
have  become  'clearly  established  law.'" 

Newsday  (NY)  (6/22,  Brune)  reports  that  qualified  immunity  "shields  police  from  being  sued  for  money  damages  in 
federal  court  for  constitutional  violations  such  as  excessive  force  unless  the  officers  broke  any  'clearly  established'  law  -  a  high 
bar  for  plaintiffs  to  overcome."  Newsday  adds  that  police  groups  argue  that  ending  qualified  immunity  "would  have  a  chilling 
effect  on  police  work,  make  them  hesitant  to  act  when  they  should  be  decisive  in  dicey  situations,  or  lead  to  retirements  and  a 
smaller  pool  of  applicants  for  police  jobs.  'Qualified  immunity  is  a  foundational  protection  for  the  policing  profession  and  any 
modification  to  this  legal  standard  will  have  a  devastating  impact  on  the  police's  ability  to  fulfill  its  public  safety  mission,'  the 
International  Association  of  Chiefs  of  Police  said  in  a  statement." 


Senate  Democrats  Threaten  To  Block  GOP  Police  Reform  Bill 

Politico  (6/22,  Everett,  Levine)  reports  Senate  Democrats  are  "strongly  signaling  they  will  filibuster  Republicans'  police 
reform  bill  later  this  week  absent  more  concessions"  from  Senate  Majority  Leader  McConnell,  who  "set  the  Senate  on  a  path  to 
consider  the  legislation  on  Wednesday."  Sen.  Jon  Tester  (D-MT)  said,  "If  nothing  changes,  I'm  voting  no.  I  need  some  assurances 
that  we're  going  to  vote  on  amendments  that  will  fix  this  bill.  And  it  needs  a  lot  of  fixing."  Senate  Minority  Leader  Schumer 
called  the  GOP  bill  "deeply  and  fundamentally  flawed." 

Reuters  Analysis:  Neither  Senate  Nor  House  Police  Reform  Bill  Likely  To  Become  Law.  Reuters  (6/22, 

Morgan)  reports  that  the  Senate  and  the  House  "will  vote  this  week  on  separate  bills  aimed  at  addressing  police 
misconduct. ..but  neither  measure  is  likely  to  become  law."  The  Senate  "is  expected  to  hold  a  procedural  vote  on  a  Republican 
bill  by  Wednesday,  while  the  House  is  due  to  vote  on  more  sweeping  Democratic  legislation  on  Thursday."  However,  Reuters 
says,  "neither  measure,  as  written,  appears  to  have  enough  bipartisan  support  to  win  approval  from  both  chambers  and  be 
signed  into  law." 

Studies  Find  Recreational  Marijuana  Laws  May  Boost  Traffic  Deaths 

The  AP  (6/22,  Tanner)  reports,  "Laws  legalizing  recreational  marijuana  may  lead  to  more  traffic  deaths,  two  new  studies 
suggest,  although  questions  remain  about  how  they  might  influence  driving  habits."  According  to  the  AP,  "Previous  research 
has  had  mixed  results  and  the  new  studies,  published  Monday  in  JAMA  Internal  Medicine,  can't  prove  that  the  traffic  death 
increases  they  found  were  caused  by  marijuana  use."  The  AP  adds,  "One  study  found  an  excess  75  traffic  deaths  per  year  after 
retail  sales  began  in  Colorado  in  January  2014,  compared  with  states  without  similar  laws,"  but  "it  found  no  similar  change  in 
Washington  state."  The  other  study  "looked  at  those  states  plus  two  others  that  allow  recreational  pot  sales,  Oregon  and 
Alaska.  If  every  state  legalized  recreational  marijuana  sales,  an  extra  6,800  people  would  die  each  year  in  traffic  accidents,  the 
researchers  calculated." 

Pandemic  Has  Increased  New  York  City  Criminal  Court  Backlog  To  More  Than  39K  Cases 

The  New  York  Times  (6/22,  Al,  Feuer,  Hong,  Weiser,  Ransom)  has  a  2,400-word  report  on  what  it  calls  New  York  City's 
"legal  limbo,"  where  "the  backlog  of  pending  cases  in  the  city's  criminal  courts  has  risen  by  nearly  a  third"  to  39,200  due  to  the 
coronavirus  pandemic.  The  Times  says  "hundreds  of  jury  trials  in  the  city  have  been  put  on  hold  indefinitely,"  and 
"arraignments,  pleas  and  evidentiary  hearings  are  being  held  by  video,  with  little  public  scrutiny." 

Massachusetts  Governor  Seeks  Training  Bonuses  For  Police  Officers 

Boston  (6/22,  Gavin)  reports,  "Police  officers  in  Massachusetts  could  receive  one-time  bonuses  of  up  to  $5,000  should 
they  take  on  additional  training  under  a  bill  filed  last  week  by  Gov.  Charlie  Baker  centered  on  creating  a  police  certification 
system."  According  to  Boston,  "The  vision  is  to  incentivize  officers  to  go  beyond  the  necessary  minimum  training  laid  out  in  the 
sweeping  proposal,  which  comes  amid  the  nationwide  movement  to  reduce  funding  for  law  enforcement,  and  instead  funnel 
resources  into  other  initiatives  such  as  anti-violence  and  public  health  programs."  The  bill,  "which  seeks  to  establish  a  system  to 
uniformly  certify,  and  de-certify,  police  officers,"  would  "provide  financial  opportunity  to  officers  to  advance  their  training  in 
key  areas,  including  first  aid,  de-escalation  tactics,  and  narcotics  training." 

San  Diego,  California  Ballot  Measure  Would  Reform  Police  Oversight,  Accountability 

The  San  Diego  Union-Tribune  M  (6/22,  Garrick)  reports  San  Diego  may  "take  a  key  step  Tuesday  toward  more  rigorous  police 
oversight,  transparency  and  accountability."  The  San  Diego  City  Council  "is  scheduled  to  evaluate  a  proposed  November  ballot 
measure  that  would  create  a  police  review  board  with  the  power  to  launch  independent  misconduct  investigations  and 
subpoena  witnesses.  While  the  proposal  has  been  in  the  works  for  several  years,  it  gained  momentum  in  the  wake  of  recent 
local  and  national  police  protests  that  have  sparked  calls  for  fundamental  law  enforcement  reforms."  The  city  "completed 
negotiations  May  21  with  the  labor  union  representing  police  officers  on  the  proposed  ballot  measure,  which  would  let  officers 
appeal  declarations  by  the  commission  that  they  are  guilty  of  misconduct." 


Join  the  IACP  on  June  24,  2020,  at  1:00  p.m.  EST  for  Part  2  and  July  16,  2020,  at  1:00  p.m.  EST  for  Part  3  of 
Mindfulness  Strategies  for  Law  Enforcement  webinar  series.  This  webinar  is  part  of  the  U.S.  Department  of 
Justice,  Bureau  of  Justice  Assistance's  National  Officer  Safety  Initiatives  Program  and  will  be  hosted  by  Mindful 
Junkie  Founder,  Gina  White.  Police  officers  across  every  rank,  dispatchers,  victim  services  personnel,  crime  scene 
personnel,  other  law  enforcement  personnel  and  family  members  are  encouraged  to  attend  these  30-minute 
interactive  mindfulness  sessions. 
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CRIME  &  DRUGS 


Swedish  Rape  Conviction  Rates  Rise  75%  After  Change  In  Law 

Reuters  (6/22,  Batha)  reports,  "Rape  conviction  rates  in  Sweden  have  risen  75%  in  two  years  following  a  major  change  in 
the  law,  spurring  calls  on  Monday  for  other  countries  to  revamp  their  legislation."  Reuters  adds,  "Sweden  changed  the  legal 
definition  of  rape  in  2018  to  sex  without  consent.  Unlike  in  many  countries,  prosecutors  do  not  have  to  prove  the  use  or  threat 
of  violence  or  coercion.  The  National  Council  on  Crime  Prevention  (Bra)  said  the  rise  in  convictions  -  up  from  190  in  2017  to  333 
in  2019  -  showed  the  change  had  had  a  greater  impact  than  expected."  According  to  Reuters,  "Britain,  Belgium,  Canada, 

Cyprus,  Germany,  Greece,  Iceland,  Ireland  and  Luxembourg  already  define  rape  as  sex  without  consent,  while  Denmark, 

Finland,  Spain  and  Portugal  have  promised  similar  reforms." 

New  York  City  Raid  Leads  To  Drug  Seizures,  Two  Arrests 

The  New  York  Post  (6/22,  Rosenberg)  reports  a  recent  raid  of  a  suspected  pill  mill  in  New  York  City  led  to  the  seizure  of 
"approximately  1.2  kilograms  of  heroin,  34  grams  of  fentanyl  and  2.3  kilograms  of  methamphetamine."  Arrested  in  connection 
with  the  raid  were  Jeison  Lebron  and  Alfredo  Goris,  who  face  "charges  of  criminal  possession  of  a  controlled  substance  and 
criminally  using  drug  paraphernalia."  The  arrests  were  the  result  of  joint  operation  conducted  by  "the  city's  Special  Narcotics 
Prosecutor,"  the  City  of  New  York  Police  Department,  and  the  DEA. 

UK  Drinkers  Barricade  Themselves  In  Pub  During  Illegal  Lockdown  Lock-In 

The  Independent  (UK)  (6/22,  Gregory)  reports,  "Drinkers  at  an  illegal  lockdown-defying  lock-in  have  barricaded 
themselves  in  a  pub  after  police  officers  arrived  to  break  up  the  session,  according  to  police."  According  to  the  Independent, 
"Merseyside  Police  officers  were  pelted  with  beer  and  other  items  as  revellers  took  up  their  fortified  position  at  the  Britannia 
Hotel  pub  in  Liverpool,  the  force  said.  There  were  reportedly  more  than  100  people  gathered  at  the  Vauxhall  pub  at  around 
midnight  on  Sunday,  playing  loud  music  and  disturbing  residents  nearby,  although  only  'a  number  of  people'  were  said  to  take 
part  in  the  blockade."  The  Independent  adds,  "Seven  men  and  one  woman,  aged  between  21  and  33,  were  arrested  for  violent 
disorder  and  drugs  offences.  Pubs  have  been  closed  by  law  for  the  last  three  months  to  fight  the  spread  of  coronavirus,  with 
Boris  Johnson  expected  to  allow  them  to  re-open  on  4  July,  albeit  with  a  range  of  new  measures  in  place  to  protect  customers." 

TECHNOLOGY 


"Blueleaks"  Hackers  Release  "Hundreds  Of  Thousands"  Of  Private  Records  On  Officers 

The  Blaze  (6/22,  Taylor)  reports  hackers  have  "leaked  highly  sensitive  police  files  from  over  200  police  departments  across 
the  country."  Activist  group  DDoSecrets  "published  what  the  outlet  calls  'hundreds  of  gigabytes'  worth  of  potentially  sensitive 
files'  from  police  departments  across  the  US."  The  group  has  "called  the  information  dump  'BlueLeaks.'"  The  group  "compiled 
the  records,  disseminating  them  into  a  searchable  database  that  can  pull  up  private  information  from  a  police  badge  number." 
Many  of  the  files  include  "information  such  as  memos,  emails,  and  officers'  personal  information".  The  group  "shared 
information  on  Twitter  regarding  the  data  dump." 


GLOBAL  SECURITY 


NYTimes  Analysis:  Antifa  Rumors  Show  Ways  Information  Spreads  Locally 

The  New  York  Times  (6/22,  Alba,  Decker)  examines  how  in  recent  weeks,  "residents  in  at  least  41  U.S.  cities  and  towns 
became  alarmed  by  rumors  that  the  loose  collective  of  anti-fascist  activists  known  as  antifa  was  headed  to  their  area,  according 
to  an  analysis  by  The  New  York  Times.  In  many  cases,  they  contacted  their  local  law  enforcement  for  help.  In  each  case,  it  was 
for  a  threat  that  never  appeared."  On  the  local  level,  the  analysis  found  that  "the  source  of  the  false  information  has  usually 
been  more  subtle,  and  shows  the  complexity  of  stunting  misinformation  online.  The  bad  information  often  first  appears  in  a 
Twitter  or  Facebook  post,  or  a  YouTube  video  there.  It  is  then  shared  on  online  spaces  like  local  Facebook  groups,  the 
neighborhood  social  networking  app  Nextdoor  and  community  texting  networks,"  which  "can  fall  under  the  radar  of  the  tech 
companies  and  online  fact  checkers." 

Black  Lives  Matter  Protests  Spread  To  White,  Rural  Areas.  The  Wall  Street  Journal  ^H(6/22,  Carlton,  Subscription 
Publication)  reports  that  the  protests  for  racial  justice  have  quickly  spread  from  big  cities  to  small,  rural  towns  that  are 
predominantly  white. 
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US  Supreme  Court  Will  Not  Revisit  Challenge  To  Qualified 
Immunity  For  Police 

<\BC  News  ^^B(6/22,  Dwyer)  reports,  "The  U.S.  Supreme  Court  on 
Monday  officially  took  a  pass  on  revisiting  its  50-year-old  doctrine  of 
qualified  immunity'  for  law  enforcement  officers,  despite  intense 
national  outcry  over  police  misconduct  and  legal  protections  that  shield 
:ops  from  liability.  'The  Supreme  Court  has  made  clear  that  they  are  not 
arepared  to  reconsider  qualified  immunity  at  this  moment,'  said  Joanna 
Schwartz,  an  expert  on  the  doctrine  at  UCLA  School  of  Law."  ABC  News 
adds,  "While  the  Civil  Rights  Act  of  1871  gives  Americans  the 
unambiguous  ability  to  sue  public  officials  over  civil  rights  violations,  the 
Supreme  Court  subsequently  limited  liability  to  only  those  rights  that 
have  become  'clearly  established  law.'" 

Newsday  (NY)  (6/22,  Brune)  reports  that  qualified  immunity  "shields  police  from  being  sued  for  money  damages  in 
federal  court  for  constitutional  violations  such  as  excessive  force  unless  the  officers  broke  any  'clearly  established'  law  -  a  high 
bar  for  plaintiffs  to  overcome."  Newsday  adds  that  police  groups  argue  that  ending  qualified  immunity  "would  have  a  chilling 
effect  on  police  work,  make  them  hesitant  to  act  when  they  should  be  decisive  in  dicey  situations,  or  lead  to  retirements  and  a 
smaller  pool  of  applicants  for  police  jobs.  'Qualified  immunity  is  a  foundational  protection  for  the  policing  profession  and  any 
modification  to  this  legal  standard  will  have  a  devastating  impact  on  the  police's  ability  to  fulfill  its  public  safety  mission,'  the 
International  Association  of  Chiefs  of  Police  said  in  a  statement." 


Senate  Democrats  Threaten  To  Block  GOP  Police  Reform  Bill 

Politico  (6/22,  Everett,  Levine)  reports  Senate  Democrats  are  "strongly  signaling  they  will  filibuster  Republicans'  police 
reform  bill  later  this  week  absent  more  concessions"  from  Senate  Majority  Leader  McConnell,  who  "set  the  Senate  on  a  path  to 
consider  the  legislation  on  Wednesday."  Sen.  Jon  Tester  (D-MT)  said,  "If  nothing  changes,  I'm  voting  no.  I  need  some  assurances 
that  we're  going  to  vote  on  amendments  that  will  fix  this  bill.  And  it  needs  a  lot  of  fixing."  Senate  Minority  Leader  Schumer 
called  the  GOP  bill  "deeply  and  fundamentally  flawed." 

Reuters  Analysis:  Neither  Senate  Nor  House  Police  Reform  Bill  Likely  To  Become  Law.  Reuters  (6/22, 

Morgan)  reports  that  the  Senate  and  the  House  "will  vote  this  week  on  separate  bills  aimed  at  addressing  police 
misconduct. ..but  neither  measure  is  likely  to  become  law."  The  Senate  "is  expected  to  hold  a  procedural  vote  on  a  Republican 
bill  by  Wednesday,  while  the  House  is  due  to  vote  on  more  sweeping  Democratic  legislation  on  Thursday."  However,  Reuters 
says,  "neither  measure,  as  written,  appears  to  have  enough  bipartisan  support  to  win  approval  from  both  chambers  and  be 
signed  into  law." 

Studies  Find  Recreational  Marijuana  Laws  May  Boost  Traffic  Deaths 

The  AP  (6/22,  Tanner)  reports,  "Laws  legalizing  recreational  marijuana  may  lead  to  more  traffic  deaths,  two  new  studies 
suggest,  although  questions  remain  about  how  they  might  influence  driving  habits."  According  to  the  AP,  "Previous  research 
has  had  mixed  results  and  the  new  studies,  published  Monday  in  JAMA  Internal  Medicine,  can't  prove  that  the  traffic  death 
increases  they  found  were  caused  by  marijuana  use."  The  AP  adds,  "One  study  found  an  excess  75  traffic  deaths  per  year  after 
retail  sales  began  in  Colorado  in  January  2014,  compared  with  states  without  similar  laws,"  but  "it  found  no  similar  change  in 
Washington  state."  The  other  study  "looked  at  those  states  plus  two  others  that  allow  recreational  pot  sales,  Oregon  and 
Alaska.  If  every  state  legalized  recreational  marijuana  sales,  an  extra  6,800  people  would  die  each  year  in  traffic  accidents,  the 
researchers  calculated." 

Pandemic  Has  Increased  New  York  City  Criminal  Court  Backlog  To  More  Than  39K  Cases 

The  New  York  Times  (6/22,  Al,  Feuer,  Hong,  Weiser,  Ransom)  has  a  2,400-word  report  on  what  it  calls  New  York  City's 
"legal  limbo,"  where  "the  backlog  of  pending  cases  in  the  city's  criminal  courts  has  risen  by  nearly  a  third"  to  39,200  due  to  the 
coronavirus  pandemic.  The  Times  says  "hundreds  of  jury  trials  in  the  city  have  been  put  on  hold  indefinitely,"  and 
"arraignments,  pleas  and  evidentiary  hearings  are  being  held  by  video,  with  little  public  scrutiny." 

Massachusetts  Governor  Seeks  Training  Bonuses  For  Police  Officers 

Boston  (6/22,  Gavin)  reports,  "Police  officers  in  Massachusetts  could  receive  one-time  bonuses  of  up  to  $5,000  should 
they  take  on  additional  training  under  a  bill  filed  last  week  by  Gov.  Charlie  Baker  centered  on  creating  a  police  certification 
system."  According  to  Boston,  "The  vision  is  to  incentivize  officers  to  go  beyond  the  necessary  minimum  training  laid  out  in  the 
sweeping  proposal,  which  comes  amid  the  nationwide  movement  to  reduce  funding  for  law  enforcement,  and  instead  funnel 
resources  into  other  initiatives  such  as  anti-violence  and  public  health  programs."  The  bill,  "which  seeks  to  establish  a  system  to 
uniformly  certify,  and  de-certify,  police  officers,"  would  "provide  financial  opportunity  to  officers  to  advance  their  training  in 
key  areas,  including  first  aid,  de-escalation  tactics,  and  narcotics  training." 

San  Diego,  California  Ballot  Measure  Would  Reform  Police  Oversight,  Accountability 

The  San  Diego  Union-Tribune  M  (6/22,  Garrick)  reports  San  Diego  may  "take  a  key  step  Tuesday  toward  more  rigorous  police 
oversight,  transparency  and  accountability."  The  San  Diego  City  Council  "is  scheduled  to  evaluate  a  proposed  November  ballot 
measure  that  would  create  a  police  review  board  with  the  power  to  launch  independent  misconduct  investigations  and 
subpoena  witnesses.  While  the  proposal  has  been  in  the  works  for  several  years,  it  gained  momentum  in  the  wake  of  recent 
local  and  national  police  protests  that  have  sparked  calls  for  fundamental  law  enforcement  reforms."  The  city  "completed 
negotiations  May  21  with  the  labor  union  representing  police  officers  on  the  proposed  ballot  measure,  which  would  let  officers 
appeal  declarations  by  the  commission  that  they  are  guilty  of  misconduct." 
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CRIME  &  DRUGS 


Swedish  Rape  Conviction  Rates  Rise  75%  After  Change  In  Law 

Reuters  (6/22,  Batha)  reports,  "Rape  conviction  rates  in  Sweden  have  risen  75%  in  two  years  following  a  major  change  in 
the  law,  spurring  calls  on  Monday  for  other  countries  to  revamp  their  legislation."  Reuters  adds,  "Sweden  changed  the  legal 
definition  of  rape  in  2018  to  sex  without  consent.  Unlike  in  many  countries,  prosecutors  do  not  have  to  prove  the  use  or  threat 
of  violence  or  coercion.  The  National  Council  on  Crime  Prevention  (Bra)  said  the  rise  in  convictions  -  up  from  190  in  2017  to  333 
in  2019  -  showed  the  change  had  had  a  greater  impact  than  expected."  According  to  Reuters,  "Britain,  Belgium,  Canada, 

Cyprus,  Germany,  Greece,  Iceland,  Ireland  and  Luxembourg  already  define  rape  as  sex  without  consent,  while  Denmark, 

Finland,  Spain  and  Portugal  have  promised  similar  reforms." 

New  York  City  Raid  Leads  To  Drug  Seizures,  Two  Arrests 

The  New  York  Post  (6/22,  Rosenberg)  reports  a  recent  raid  of  a  suspected  pill  mill  in  New  York  City  led  to  the  seizure  of 
"approximately  1.2  kilograms  of  heroin,  34  grams  of  fentanyl  and  2.3  kilograms  of  methamphetamine."  Arrested  in  connection 
with  the  raid  were  Jeison  Lebron  and  Alfredo  Goris,  who  face  "charges  of  criminal  possession  of  a  controlled  substance  and 
criminally  using  drug  paraphernalia."  The  arrests  were  the  result  of  joint  operation  conducted  by  "the  city's  Special  Narcotics 
Prosecutor,"  the  City  of  New  York  Police  Department,  and  the  DEA. 

UK  Drinkers  Barricade  Themselves  In  Pub  During  Illegal  Lockdown  Lock-In 

The  Independent  (UK)  (6/22,  Gregory)  reports,  "Drinkers  at  an  illegal  lockdown-defying  lock-in  have  barricaded 
themselves  in  a  pub  after  police  officers  arrived  to  break  up  the  session,  according  to  police."  According  to  the  Independent, 
"Merseyside  Police  officers  were  pelted  with  beer  and  other  items  as  revellers  took  up  their  fortified  position  at  the  Britannia 
Hotel  pub  in  Liverpool,  the  force  said.  There  were  reportedly  more  than  100  people  gathered  at  the  Vauxhall  pub  at  around 
midnight  on  Sunday,  playing  loud  music  and  disturbing  residents  nearby,  although  only  'a  number  of  people'  were  said  to  take 
part  in  the  blockade."  The  Independent  adds,  "Seven  men  and  one  woman,  aged  between  21  and  33,  were  arrested  for  violent 
disorder  and  drugs  offences.  Pubs  have  been  closed  by  law  for  the  last  three  months  to  fight  the  spread  of  coronavirus,  with 
Boris  Johnson  expected  to  allow  them  to  re-open  on  4  July,  albeit  with  a  range  of  new  measures  in  place  to  protect  customers." 

TECHNOLOGY 


"Blueleaks"  Hackers  Release  "Hundreds  Of  Thousands"  Of  Private  Records  On  Officers 

The  Blaze  (6/22,  Taylor)  reports  hackers  have  "leaked  highly  sensitive  police  files  from  over  200  police  departments  across 
the  country."  Activist  group  DDoSecrets  "published  what  the  outlet  calls  'hundreds  of  gigabytes'  worth  of  potentially  sensitive 
files'  from  police  departments  across  the  US."  The  group  has  "called  the  information  dump  'BlueLeaks.'"  The  group  "compiled 
the  records,  disseminating  them  into  a  searchable  database  that  can  pull  up  private  information  from  a  police  badge  number." 
Many  of  the  files  include  "information  such  as  memos,  emails,  and  officers'  personal  information".  The  group  "shared 
information  on  Twitter  regarding  the  data  dump." 


GLOBAL  SECURITY 


NYTimes  Analysis:  Antifa  Rumors  Show  Ways  Information  Spreads  Locally 

The  New  York  Times  (6/22,  Alba,  Decker)  examines  how  in  recent  weeks,  "residents  in  at  least  41  U.S.  cities  and  towns 
became  alarmed  by  rumors  that  the  loose  collective  of  anti-fascist  activists  known  as  antifa  was  headed  to  their  area,  according 
to  an  analysis  by  The  New  York  Times.  In  many  cases,  they  contacted  their  local  law  enforcement  for  help.  In  each  case,  it  was 
for  a  threat  that  never  appeared."  On  the  local  level,  the  analysis  found  that  "the  source  of  the  false  information  has  usually 
been  more  subtle,  and  shows  the  complexity  of  stunting  misinformation  online.  The  bad  information  often  first  appears  in  a 
Twitter  or  Facebook  post,  or  a  YouTube  video  there.  It  is  then  shared  on  online  spaces  like  local  Facebook  groups,  the 
neighborhood  social  networking  app  Nextdoor  and  community  texting  networks,"  which  "can  fall  under  the  radar  of  the  tech 
companies  and  online  fact  checkers." 

Black  Lives  Matter  Protests  Spread  To  White,  Rural  Areas.  The  Wall  Street  Journal  ^H(6/22,  Carlton,  Subscription 
Publication)  reports  that  the  protests  for  racial  justice  have  quickly  spread  from  big  cities  to  small,  rural  towns  that  are 
predominantly  white. 
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US  Supreme  Court  Will  Not  Revisit  Challenge  To  Qualified 
Immunity  For  Police 

<\BC  News  ^^B(6/22,  Dwyer)  reports,  "The  U.S.  Supreme  Court  on 
Monday  officially  took  a  pass  on  revisiting  its  50-year-old  doctrine  of 
qualified  immunity'  for  law  enforcement  officers,  despite  intense 
national  outcry  over  police  misconduct  and  legal  protections  that  shield 
:ops  from  liability.  'The  Supreme  Court  has  made  clear  that  they  are  not 
arepared  to  reconsider  qualified  immunity  at  this  moment,'  said  Joanna 
Schwartz,  an  expert  on  the  doctrine  at  UCLA  School  of  Law."  ABC  News 
adds,  "While  the  Civil  Rights  Act  of  1871  gives  Americans  the 
unambiguous  ability  to  sue  public  officials  over  civil  rights  violations,  the 
Supreme  Court  subsequently  limited  liability  to  only  those  rights  that 
have  become  'clearly  established  law.'" 

Newsday  (NY)  (6/22,  Brune)  reports  that  qualified  immunity  "shields  police  from  being  sued  for  money  damages  in 
federal  court  for  constitutional  violations  such  as  excessive  force  unless  the  officers  broke  any  'clearly  established'  law  -  a  high 
bar  for  plaintiffs  to  overcome."  Newsday  adds  that  police  groups  argue  that  ending  qualified  immunity  "would  have  a  chilling 
effect  on  police  work,  make  them  hesitant  to  act  when  they  should  be  decisive  in  dicey  situations,  or  lead  to  retirements  and  a 
smaller  pool  of  applicants  for  police  jobs.  'Qualified  immunity  is  a  foundational  protection  for  the  policing  profession  and  any 
modification  to  this  legal  standard  will  have  a  devastating  impact  on  the  police's  ability  to  fulfill  its  public  safety  mission,'  the 
International  Association  of  Chiefs  of  Police  said  in  a  statement." 


Senate  Democrats  Threaten  To  Block  GOP  Police  Reform  Bill 

Politico  (6/22,  Everett,  Levine)  reports  Senate  Democrats  are  "strongly  signaling  they  will  filibuster  Republicans'  police 
reform  bill  later  this  week  absent  more  concessions"  from  Senate  Majority  Leader  McConnell,  who  "set  the  Senate  on  a  path  to 
consider  the  legislation  on  Wednesday."  Sen.  Jon  Tester  (D-MT)  said,  "If  nothing  changes,  I'm  voting  no.  I  need  some  assurances 
that  we're  going  to  vote  on  amendments  that  will  fix  this  bill.  And  it  needs  a  lot  of  fixing."  Senate  Minority  Leader  Schumer 
called  the  GOP  bill  "deeply  and  fundamentally  flawed." 

Reuters  Analysis:  Neither  Senate  Nor  House  Police  Reform  Bill  Likely  To  Become  Law.  Reuters  (6/22, 

Morgan)  reports  that  the  Senate  and  the  House  "will  vote  this  week  on  separate  bills  aimed  at  addressing  police 
misconduct. ..but  neither  measure  is  likely  to  become  law."  The  Senate  "is  expected  to  hold  a  procedural  vote  on  a  Republican 
bill  by  Wednesday,  while  the  House  is  due  to  vote  on  more  sweeping  Democratic  legislation  on  Thursday."  However,  Reuters 
says,  "neither  measure,  as  written,  appears  to  have  enough  bipartisan  support  to  win  approval  from  both  chambers  and  be 
signed  into  law." 

Studies  Find  Recreational  Marijuana  Laws  May  Boost  Traffic  Deaths 

The  AP  (6/22,  Tanner)  reports,  "Laws  legalizing  recreational  marijuana  may  lead  to  more  traffic  deaths,  two  new  studies 
suggest,  although  questions  remain  about  how  they  might  influence  driving  habits."  According  to  the  AP,  "Previous  research 
has  had  mixed  results  and  the  new  studies,  published  Monday  in  JAMA  Internal  Medicine,  can't  prove  that  the  traffic  death 
increases  they  found  were  caused  by  marijuana  use."  The  AP  adds,  "One  study  found  an  excess  75  traffic  deaths  per  year  after 
retail  sales  began  in  Colorado  in  January  2014,  compared  with  states  without  similar  laws,"  but  "it  found  no  similar  change  in 
Washington  state."  The  other  study  "looked  at  those  states  plus  two  others  that  allow  recreational  pot  sales,  Oregon  and 
Alaska.  If  every  state  legalized  recreational  marijuana  sales,  an  extra  6,800  people  would  die  each  year  in  traffic  accidents,  the 
researchers  calculated." 

Pandemic  Has  Increased  New  York  City  Criminal  Court  Backlog  To  More  Than  39K  Cases 

The  New  York  Times  (6/22,  Al,  Feuer,  Hong,  Weiser,  Ransom)  has  a  2,400-word  report  on  what  it  calls  New  York  City's 
"legal  limbo,"  where  "the  backlog  of  pending  cases  in  the  city's  criminal  courts  has  risen  by  nearly  a  third"  to  39,200  due  to  the 
coronavirus  pandemic.  The  Times  says  "hundreds  of  jury  trials  in  the  city  have  been  put  on  hold  indefinitely,"  and 
"arraignments,  pleas  and  evidentiary  hearings  are  being  held  by  video,  with  little  public  scrutiny." 

Massachusetts  Governor  Seeks  Training  Bonuses  For  Police  Officers 

Boston  (6/22,  Gavin)  reports,  "Police  officers  in  Massachusetts  could  receive  one-time  bonuses  of  up  to  $5,000  should 
they  take  on  additional  training  under  a  bill  filed  last  week  by  Gov.  Charlie  Baker  centered  on  creating  a  police  certification 
system."  According  to  Boston,  "The  vision  is  to  incentivize  officers  to  go  beyond  the  necessary  minimum  training  laid  out  in  the 
sweeping  proposal,  which  comes  amid  the  nationwide  movement  to  reduce  funding  for  law  enforcement,  and  instead  funnel 
resources  into  other  initiatives  such  as  anti-violence  and  public  health  programs."  The  bill,  "which  seeks  to  establish  a  system  to 
uniformly  certify,  and  de-certify,  police  officers,"  would  "provide  financial  opportunity  to  officers  to  advance  their  training  in 
key  areas,  including  first  aid,  de-escalation  tactics,  and  narcotics  training." 

San  Diego,  California  Ballot  Measure  Would  Reform  Police  Oversight,  Accountability 

The  San  Diego  Union-Tribune  M  (6/22,  Garrick)  reports  San  Diego  may  "take  a  key  step  Tuesday  toward  more  rigorous  police 
oversight,  transparency  and  accountability."  The  San  Diego  City  Council  "is  scheduled  to  evaluate  a  proposed  November  ballot 
measure  that  would  create  a  police  review  board  with  the  power  to  launch  independent  misconduct  investigations  and 
subpoena  witnesses.  While  the  proposal  has  been  in  the  works  for  several  years,  it  gained  momentum  in  the  wake  of  recent 
local  and  national  police  protests  that  have  sparked  calls  for  fundamental  law  enforcement  reforms."  The  city  "completed 
negotiations  May  21  with  the  labor  union  representing  police  officers  on  the  proposed  ballot  measure,  which  would  let  officers 
appeal  declarations  by  the  commission  that  they  are  guilty  of  misconduct." 
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Swedish  Rape  Conviction  Rates  Rise  75%  After  Change  In  Law 

Reuters  (6/22,  Batha)  reports,  "Rape  conviction  rates  in  Sweden  have  risen  75%  in  two  years  following  a  major  change  in 
the  law,  spurring  calls  on  Monday  for  other  countries  to  revamp  their  legislation."  Reuters  adds,  "Sweden  changed  the  legal 
definition  of  rape  in  2018  to  sex  without  consent.  Unlike  in  many  countries,  prosecutors  do  not  have  to  prove  the  use  or  threat 
of  violence  or  coercion.  The  National  Council  on  Crime  Prevention  (Bra)  said  the  rise  in  convictions  -  up  from  190  in  2017  to  333 
in  2019  -  showed  the  change  had  had  a  greater  impact  than  expected."  According  to  Reuters,  "Britain,  Belgium,  Canada, 

Cyprus,  Germany,  Greece,  Iceland,  Ireland  and  Luxembourg  already  define  rape  as  sex  without  consent,  while  Denmark, 

Finland,  Spain  and  Portugal  have  promised  similar  reforms." 

New  York  City  Raid  Leads  To  Drug  Seizures,  Two  Arrests 

The  New  York  Post  (6/22,  Rosenberg)  reports  a  recent  raid  of  a  suspected  pill  mill  in  New  York  City  led  to  the  seizure  of 
"approximately  1.2  kilograms  of  heroin,  34  grams  of  fentanyl  and  2.3  kilograms  of  methamphetamine."  Arrested  in  connection 
with  the  raid  were  Jeison  Lebron  and  Alfredo  Goris,  who  face  "charges  of  criminal  possession  of  a  controlled  substance  and 
criminally  using  drug  paraphernalia."  The  arrests  were  the  result  of  joint  operation  conducted  by  "the  city's  Special  Narcotics 
Prosecutor,"  the  City  of  New  York  Police  Department,  and  the  DEA. 

UK  Drinkers  Barricade  Themselves  In  Pub  During  Illegal  Lockdown  Lock-In 

The  Independent  (UK)  (6/22,  Gregory)  reports,  "Drinkers  at  an  illegal  lockdown-defying  lock-in  have  barricaded 
themselves  in  a  pub  after  police  officers  arrived  to  break  up  the  session,  according  to  police."  According  to  the  Independent, 
"Merseyside  Police  officers  were  pelted  with  beer  and  other  items  as  revellers  took  up  their  fortified  position  at  the  Britannia 
Hotel  pub  in  Liverpool,  the  force  said.  There  were  reportedly  more  than  100  people  gathered  at  the  Vauxhall  pub  at  around 
midnight  on  Sunday,  playing  loud  music  and  disturbing  residents  nearby,  although  only  'a  number  of  people'  were  said  to  take 
part  in  the  blockade."  The  Independent  adds,  "Seven  men  and  one  woman,  aged  between  21  and  33,  were  arrested  for  violent 
disorder  and  drugs  offences.  Pubs  have  been  closed  by  law  for  the  last  three  months  to  fight  the  spread  of  coronavirus,  with 
Boris  Johnson  expected  to  allow  them  to  re-open  on  4  July,  albeit  with  a  range  of  new  measures  in  place  to  protect  customers." 

TECHNOLOGY 


"Blueleaks"  Hackers  Release  "Hundreds  Of  Thousands"  Of  Private  Records  On  Officers 

The  Blaze  (6/22,  Taylor)  reports  hackers  have  "leaked  highly  sensitive  police  files  from  over  200  police  departments  across 
the  country."  Activist  group  DDoSecrets  "published  what  the  outlet  calls  'hundreds  of  gigabytes'  worth  of  potentially  sensitive 
files'  from  police  departments  across  the  US."  The  group  has  "called  the  information  dump  'BlueLeaks.'"  The  group  "compiled 
the  records,  disseminating  them  into  a  searchable  database  that  can  pull  up  private  information  from  a  police  badge  number." 
Many  of  the  files  include  "information  such  as  memos,  emails,  and  officers'  personal  information".  The  group  "shared 
information  on  Twitter  regarding  the  data  dump." 


GLOBAL  SECURITY 


NYTimes  Analysis:  Antifa  Rumors  Show  Ways  Information  Spreads  Locally 

The  New  York  Times  (6/22,  Alba,  Decker)  examines  how  in  recent  weeks,  "residents  in  at  least  41  U.S.  cities  and  towns 
became  alarmed  by  rumors  that  the  loose  collective  of  anti-fascist  activists  known  as  antifa  was  headed  to  their  area,  according 
to  an  analysis  by  The  New  York  Times.  In  many  cases,  they  contacted  their  local  law  enforcement  for  help.  In  each  case,  it  was 
for  a  threat  that  never  appeared."  On  the  local  level,  the  analysis  found  that  "the  source  of  the  false  information  has  usually 
been  more  subtle,  and  shows  the  complexity  of  stunting  misinformation  online.  The  bad  information  often  first  appears  in  a 
Twitter  or  Facebook  post,  or  a  YouTube  video  there.  It  is  then  shared  on  online  spaces  like  local  Facebook  groups,  the 
neighborhood  social  networking  app  Nextdoor  and  community  texting  networks,"  which  "can  fall  under  the  radar  of  the  tech 
companies  and  online  fact  checkers." 

Black  Lives  Matter  Protests  Spread  To  White,  Rural  Areas.  The  Wall  Street  Journal  ^H(6/22,  Carlton,  Subscription 
Publication)  reports  that  the  protests  for  racial  justice  have  quickly  spread  from  big  cities  to  small,  rural  towns  that  are 
predominantly  white. 
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POLICING  &  POLICY 


US  Supreme  Court  Will  Not  Revisit  Challenge  To  Qualified 
Immunity  For  Police 

<\BC  News  ^^B(6/22,  Dwyer)  reports,  "The  U.S.  Supreme  Court  on 
Monday  officially  took  a  pass  on  revisiting  its  50-year-old  doctrine  of 
qualified  immunity'  for  law  enforcement  officers,  despite  intense 
national  outcry  over  police  misconduct  and  legal  protections  that  shield 
:ops  from  liability.  'The  Supreme  Court  has  made  clear  that  they  are  not 
arepared  to  reconsider  qualified  immunity  at  this  moment,'  said  Joanna 
Schwartz,  an  expert  on  the  doctrine  at  UCLA  School  of  Law."  ABC  News 
adds,  "While  the  Civil  Rights  Act  of  1871  gives  Americans  the 
unambiguous  ability  to  sue  public  officials  over  civil  rights  violations,  the 
Supreme  Court  subsequently  limited  liability  to  only  those  rights  that 
have  become  'clearly  established  law.'" 

Newsday  (NY)  (6/22,  Brune)  reports  that  qualified  immunity  "shields  police  from  being  sued  for  money  damages  in 
federal  court  for  constitutional  violations  such  as  excessive  force  unless  the  officers  broke  any  'clearly  established'  law  -  a  high 
bar  for  plaintiffs  to  overcome."  Newsday  adds  that  police  groups  argue  that  ending  qualified  immunity  "would  have  a  chilling 
effect  on  police  work,  make  them  hesitant  to  act  when  they  should  be  decisive  in  dicey  situations,  or  lead  to  retirements  and  a 
smaller  pool  of  applicants  for  police  jobs.  'Qualified  immunity  is  a  foundational  protection  for  the  policing  profession  and  any 
modification  to  this  legal  standard  will  have  a  devastating  impact  on  the  police's  ability  to  fulfill  its  public  safety  mission,'  the 
International  Association  of  Chiefs  of  Police  said  in  a  statement." 


Senate  Democrats  Threaten  To  Block  GOP  Police  Reform  Bill 

Politico  (6/22,  Everett,  Levine)  reports  Senate  Democrats  are  "strongly  signaling  they  will  filibuster  Republicans'  police 
reform  bill  later  this  week  absent  more  concessions"  from  Senate  Majority  Leader  McConnell,  who  "set  the  Senate  on  a  path  to 
consider  the  legislation  on  Wednesday."  Sen.  Jon  Tester  (D-MT)  said,  "If  nothing  changes,  I'm  voting  no.  I  need  some  assurances 
that  we're  going  to  vote  on  amendments  that  will  fix  this  bill.  And  it  needs  a  lot  of  fixing."  Senate  Minority  Leader  Schumer 
called  the  GOP  bill  "deeply  and  fundamentally  flawed." 

Reuters  Analysis:  Neither  Senate  Nor  House  Police  Reform  Bill  Likely  To  Become  Law.  Reuters  (6/22, 

Morgan)  reports  that  the  Senate  and  the  House  "will  vote  this  week  on  separate  bills  aimed  at  addressing  police 
misconduct. ..but  neither  measure  is  likely  to  become  law."  The  Senate  "is  expected  to  hold  a  procedural  vote  on  a  Republican 
bill  by  Wednesday,  while  the  House  is  due  to  vote  on  more  sweeping  Democratic  legislation  on  Thursday."  However,  Reuters 
says,  "neither  measure,  as  written,  appears  to  have  enough  bipartisan  support  to  win  approval  from  both  chambers  and  be 
signed  into  law." 

Studies  Find  Recreational  Marijuana  Laws  May  Boost  Traffic  Deaths 

The  AP  (6/22,  Tanner)  reports,  "Laws  legalizing  recreational  marijuana  may  lead  to  more  traffic  deaths,  two  new  studies 
suggest,  although  questions  remain  about  how  they  might  influence  driving  habits."  According  to  the  AP,  "Previous  research 
has  had  mixed  results  and  the  new  studies,  published  Monday  in  JAMA  Internal  Medicine,  can't  prove  that  the  traffic  death 
increases  they  found  were  caused  by  marijuana  use."  The  AP  adds,  "One  study  found  an  excess  75  traffic  deaths  per  year  after 
retail  sales  began  in  Colorado  in  January  2014,  compared  with  states  without  similar  laws,"  but  "it  found  no  similar  change  in 
Washington  state."  The  other  study  "looked  at  those  states  plus  two  others  that  allow  recreational  pot  sales,  Oregon  and 
Alaska.  If  every  state  legalized  recreational  marijuana  sales,  an  extra  6,800  people  would  die  each  year  in  traffic  accidents,  the 
researchers  calculated." 

Pandemic  Has  Increased  New  York  City  Criminal  Court  Backlog  To  More  Than  39K  Cases 

The  New  York  Times  (6/22,  Al,  Feuer,  Hong,  Weiser,  Ransom)  has  a  2,400-word  report  on  what  it  calls  New  York  City's 
"legal  limbo,"  where  "the  backlog  of  pending  cases  in  the  city's  criminal  courts  has  risen  by  nearly  a  third"  to  39,200  due  to  the 
coronavirus  pandemic.  The  Times  says  "hundreds  of  jury  trials  in  the  city  have  been  put  on  hold  indefinitely,"  and 
"arraignments,  pleas  and  evidentiary  hearings  are  being  held  by  video,  with  little  public  scrutiny." 

Massachusetts  Governor  Seeks  Training  Bonuses  For  Police  Officers 

Boston  (6/22,  Gavin)  reports,  "Police  officers  in  Massachusetts  could  receive  one-time  bonuses  of  up  to  $5,000  should 
they  take  on  additional  training  under  a  bill  filed  last  week  by  Gov.  Charlie  Baker  centered  on  creating  a  police  certification 
system."  According  to  Boston,  "The  vision  is  to  incentivize  officers  to  go  beyond  the  necessary  minimum  training  laid  out  in  the 
sweeping  proposal,  which  comes  amid  the  nationwide  movement  to  reduce  funding  for  law  enforcement,  and  instead  funnel 
resources  into  other  initiatives  such  as  anti-violence  and  public  health  programs."  The  bill,  "which  seeks  to  establish  a  system  to 
uniformly  certify,  and  de-certify,  police  officers,"  would  "provide  financial  opportunity  to  officers  to  advance  their  training  in 
key  areas,  including  first  aid,  de-escalation  tactics,  and  narcotics  training." 

San  Diego,  California  Ballot  Measure  Would  Reform  Police  Oversight,  Accountability 

The  San  Diego  Union-Tribune  M  (6/22,  Garrick)  reports  San  Diego  may  "take  a  key  step  Tuesday  toward  more  rigorous  police 
oversight,  transparency  and  accountability."  The  San  Diego  City  Council  "is  scheduled  to  evaluate  a  proposed  November  ballot 
measure  that  would  create  a  police  review  board  with  the  power  to  launch  independent  misconduct  investigations  and 
subpoena  witnesses.  While  the  proposal  has  been  in  the  works  for  several  years,  it  gained  momentum  in  the  wake  of  recent 
local  and  national  police  protests  that  have  sparked  calls  for  fundamental  law  enforcement  reforms."  The  city  "completed 
negotiations  May  21  with  the  labor  union  representing  police  officers  on  the  proposed  ballot  measure,  which  would  let  officers 
appeal  declarations  by  the  commission  that  they  are  guilty  of  misconduct." 


Join  the  IACP  on  June  24,  2020,  at  1:00  p.m.  EST  for  Part  2  and  July  16,  2020,  at  1:00  p.m.  EST  for  Part  3  of 
Mindfulness  Strategies  for  Law  Enforcement  webinar  series.  This  webinar  is  part  of  the  U.S.  Department  of 
Justice,  Bureau  of  Justice  Assistance's  National  Officer  Safety  Initiatives  Program  and  will  be  hosted  by  Mindful 
Junkie  Founder,  Gina  White.  Police  officers  across  every  rank,  dispatchers,  victim  services  personnel,  crime  scene 
personnel,  other  law  enforcement  personnel  and  family  members  are  encouraged  to  attend  these  30-minute 
interactive  mindfulness  sessions. 
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Swedish  Rape  Conviction  Rates  Rise  75%  After  Change  In  Law 

Reuters  (6/22,  Batha)  reports,  "Rape  conviction  rates  in  Sweden  have  risen  75%  in  two  years  following  a  major  change  in 
the  law,  spurring  calls  on  Monday  for  other  countries  to  revamp  their  legislation."  Reuters  adds,  "Sweden  changed  the  legal 
definition  of  rape  in  2018  to  sex  without  consent.  Unlike  in  many  countries,  prosecutors  do  not  have  to  prove  the  use  or  threat 
of  violence  or  coercion.  The  National  Council  on  Crime  Prevention  (Bra)  said  the  rise  in  convictions  -  up  from  190  in  2017  to  333 
in  2019  -  showed  the  change  had  had  a  greater  impact  than  expected."  According  to  Reuters,  "Britain,  Belgium,  Canada, 

Cyprus,  Germany,  Greece,  Iceland,  Ireland  and  Luxembourg  already  define  rape  as  sex  without  consent,  while  Denmark, 

Finland,  Spain  and  Portugal  have  promised  similar  reforms." 

New  York  City  Raid  Leads  To  Drug  Seizures,  Two  Arrests 

The  New  York  Post  (6/22,  Rosenberg)  reports  a  recent  raid  of  a  suspected  pill  mill  in  New  York  City  led  to  the  seizure  of 
"approximately  1.2  kilograms  of  heroin,  34  grams  of  fentanyl  and  2.3  kilograms  of  methamphetamine."  Arrested  in  connection 
with  the  raid  were  Jeison  Lebron  and  Alfredo  Goris,  who  face  "charges  of  criminal  possession  of  a  controlled  substance  and 
criminally  using  drug  paraphernalia."  The  arrests  were  the  result  of  joint  operation  conducted  by  "the  city's  Special  Narcotics 
Prosecutor,"  the  City  of  New  York  Police  Department,  and  the  DEA. 

UK  Drinkers  Barricade  Themselves  In  Pub  During  Illegal  Lockdown  Lock-In 

The  Independent  (UK)  (6/22,  Gregory)  reports,  "Drinkers  at  an  illegal  lockdown-defying  lock-in  have  barricaded 
themselves  in  a  pub  after  police  officers  arrived  to  break  up  the  session,  according  to  police."  According  to  the  Independent, 
"Merseyside  Police  officers  were  pelted  with  beer  and  other  items  as  revellers  took  up  their  fortified  position  at  the  Britannia 
Hotel  pub  in  Liverpool,  the  force  said.  There  were  reportedly  more  than  100  people  gathered  at  the  Vauxhall  pub  at  around 
midnight  on  Sunday,  playing  loud  music  and  disturbing  residents  nearby,  although  only  'a  number  of  people'  were  said  to  take 
part  in  the  blockade."  The  Independent  adds,  "Seven  men  and  one  woman,  aged  between  21  and  33,  were  arrested  for  violent 
disorder  and  drugs  offences.  Pubs  have  been  closed  by  law  for  the  last  three  months  to  fight  the  spread  of  coronavirus,  with 
Boris  Johnson  expected  to  allow  them  to  re-open  on  4  July,  albeit  with  a  range  of  new  measures  in  place  to  protect  customers." 

TECHNOLOGY 


"Blueleaks"  Hackers  Release  "Hundreds  Of  Thousands"  Of  Private  Records  On  Officers 

The  Blaze  (6/22,  Taylor)  reports  hackers  have  "leaked  highly  sensitive  police  files  from  over  200  police  departments  across 
the  country."  Activist  group  DDoSecrets  "published  what  the  outlet  calls  'hundreds  of  gigabytes'  worth  of  potentially  sensitive 
files'  from  police  departments  across  the  US."  The  group  has  "called  the  information  dump  'BlueLeaks.'"  The  group  "compiled 
the  records,  disseminating  them  into  a  searchable  database  that  can  pull  up  private  information  from  a  police  badge  number." 
Many  of  the  files  include  "information  such  as  memos,  emails,  and  officers'  personal  information".  The  group  "shared 
information  on  Twitter  regarding  the  data  dump." 


GLOBAL  SECURITY 


NYTimes  Analysis:  Antifa  Rumors  Show  Ways  Information  Spreads  Locally 

The  New  York  Times  (6/22,  Alba,  Decker)  examines  how  in  recent  weeks,  "residents  in  at  least  41  U.S.  cities  and  towns 
became  alarmed  by  rumors  that  the  loose  collective  of  anti-fascist  activists  known  as  antifa  was  headed  to  their  area,  according 
to  an  analysis  by  The  New  York  Times.  In  many  cases,  they  contacted  their  local  law  enforcement  for  help.  In  each  case,  it  was 
for  a  threat  that  never  appeared."  On  the  local  level,  the  analysis  found  that  "the  source  of  the  false  information  has  usually 
been  more  subtle,  and  shows  the  complexity  of  stunting  misinformation  online.  The  bad  information  often  first  appears  in  a 
Twitter  or  Facebook  post,  or  a  YouTube  video  there.  It  is  then  shared  on  online  spaces  like  local  Facebook  groups,  the 
neighborhood  social  networking  app  Nextdoor  and  community  texting  networks,"  which  "can  fall  under  the  radar  of  the  tech 
companies  and  online  fact  checkers." 

Black  Lives  Matter  Protests  Spread  To  White,  Rural  Areas.  The  Wall  Street  Journal  ^H(6/22,  Carlton,  Subscription 
Publication)  reports  that  the  protests  for  racial  justice  have  quickly  spread  from  big  cities  to  small,  rural  towns  that  are 
predominantly  white. 
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US  Supreme  Court  Will  Not  Revisit  Challenge  To  Qualified 
Immunity  For  Police 

<\BC  News  ^^B(6/22,  Dwyer)  reports,  "The  U.S.  Supreme  Court  on 
Monday  officially  took  a  pass  on  revisiting  its  50-year-old  doctrine  of 
qualified  immunity'  for  law  enforcement  officers,  despite  intense 
national  outcry  over  police  misconduct  and  legal  protections  that  shield 
:ops  from  liability.  'The  Supreme  Court  has  made  clear  that  they  are  not 
arepared  to  reconsider  qualified  immunity  at  this  moment,'  said  Joanna 
Schwartz,  an  expert  on  the  doctrine  at  UCLA  School  of  Law."  ABC  News 
adds,  "While  the  Civil  Rights  Act  of  1871  gives  Americans  the 
unambiguous  ability  to  sue  public  officials  over  civil  rights  violations,  the 
Supreme  Court  subsequently  limited  liability  to  only  those  rights  that 
have  become  'clearly  established  law.'" 

Newsday  (NY)  (6/22,  Brune)  reports  that  qualified  immunity  "shields  police  from  being  sued  for  money  damages  in 
federal  court  for  constitutional  violations  such  as  excessive  force  unless  the  officers  broke  any  'clearly  established'  law  -  a  high 
bar  for  plaintiffs  to  overcome."  Newsday  adds  that  police  groups  argue  that  ending  qualified  immunity  "would  have  a  chilling 
effect  on  police  work,  make  them  hesitant  to  act  when  they  should  be  decisive  in  dicey  situations,  or  lead  to  retirements  and  a 
smaller  pool  of  applicants  for  police  jobs.  'Qualified  immunity  is  a  foundational  protection  for  the  policing  profession  and  any 
modification  to  this  legal  standard  will  have  a  devastating  impact  on  the  police's  ability  to  fulfill  its  public  safety  mission,'  the 
International  Association  of  Chiefs  of  Police  said  in  a  statement." 


Senate  Democrats  Threaten  To  Block  GOP  Police  Reform  Bill 

Politico  (6/22,  Everett,  Levine)  reports  Senate  Democrats  are  "strongly  signaling  they  will  filibuster  Republicans'  police 
reform  bill  later  this  week  absent  more  concessions"  from  Senate  Majority  Leader  McConnell,  who  "set  the  Senate  on  a  path  to 
consider  the  legislation  on  Wednesday."  Sen.  Jon  Tester  (D-MT)  said,  "If  nothing  changes,  I'm  voting  no.  I  need  some  assurances 
that  we're  going  to  vote  on  amendments  that  will  fix  this  bill.  And  it  needs  a  lot  of  fixing."  Senate  Minority  Leader  Schumer 
called  the  GOP  bill  "deeply  and  fundamentally  flawed." 

Reuters  Analysis:  Neither  Senate  Nor  House  Police  Reform  Bill  Likely  To  Become  Law.  Reuters  (6/22, 

Morgan)  reports  that  the  Senate  and  the  House  "will  vote  this  week  on  separate  bills  aimed  at  addressing  police 
misconduct. ..but  neither  measure  is  likely  to  become  law."  The  Senate  "is  expected  to  hold  a  procedural  vote  on  a  Republican 
bill  by  Wednesday,  while  the  House  is  due  to  vote  on  more  sweeping  Democratic  legislation  on  Thursday."  However,  Reuters 
says,  "neither  measure,  as  written,  appears  to  have  enough  bipartisan  support  to  win  approval  from  both  chambers  and  be 
signed  into  law." 

Studies  Find  Recreational  Marijuana  Laws  May  Boost  Traffic  Deaths 

The  AP  (6/22,  Tanner)  reports,  "Laws  legalizing  recreational  marijuana  may  lead  to  more  traffic  deaths,  two  new  studies 
suggest,  although  questions  remain  about  how  they  might  influence  driving  habits."  According  to  the  AP,  "Previous  research 
has  had  mixed  results  and  the  new  studies,  published  Monday  in  JAMA  Internal  Medicine,  can't  prove  that  the  traffic  death 
increases  they  found  were  caused  by  marijuana  use."  The  AP  adds,  "One  study  found  an  excess  75  traffic  deaths  per  year  after 
retail  sales  began  in  Colorado  in  January  2014,  compared  with  states  without  similar  laws,"  but  "it  found  no  similar  change  in 
Washington  state."  The  other  study  "looked  at  those  states  plus  two  others  that  allow  recreational  pot  sales,  Oregon  and 
Alaska.  If  every  state  legalized  recreational  marijuana  sales,  an  extra  6,800  people  would  die  each  year  in  traffic  accidents,  the 
researchers  calculated." 

Pandemic  Has  Increased  New  York  City  Criminal  Court  Backlog  To  More  Than  39K  Cases 

The  New  York  Times  (6/22,  Al,  Feuer,  Hong,  Weiser,  Ransom)  has  a  2,400-word  report  on  what  it  calls  New  York  City's 
"legal  limbo,"  where  "the  backlog  of  pending  cases  in  the  city's  criminal  courts  has  risen  by  nearly  a  third"  to  39,200  due  to  the 
coronavirus  pandemic.  The  Times  says  "hundreds  of  jury  trials  in  the  city  have  been  put  on  hold  indefinitely,"  and 
"arraignments,  pleas  and  evidentiary  hearings  are  being  held  by  video,  with  little  public  scrutiny." 

Massachusetts  Governor  Seeks  Training  Bonuses  For  Police  Officers 

Boston  (6/22,  Gavin)  reports,  "Police  officers  in  Massachusetts  could  receive  one-time  bonuses  of  up  to  $5,000  should 
they  take  on  additional  training  under  a  bill  filed  last  week  by  Gov.  Charlie  Baker  centered  on  creating  a  police  certification 
system."  According  to  Boston,  "The  vision  is  to  incentivize  officers  to  go  beyond  the  necessary  minimum  training  laid  out  in  the 
sweeping  proposal,  which  comes  amid  the  nationwide  movement  to  reduce  funding  for  law  enforcement,  and  instead  funnel 
resources  into  other  initiatives  such  as  anti-violence  and  public  health  programs."  The  bill,  "which  seeks  to  establish  a  system  to 
uniformly  certify,  and  de-certify,  police  officers,"  would  "provide  financial  opportunity  to  officers  to  advance  their  training  in 
key  areas,  including  first  aid,  de-escalation  tactics,  and  narcotics  training." 

San  Diego,  California  Ballot  Measure  Would  Reform  Police  Oversight,  Accountability 

The  San  Diego  Union-Tribune  M  (6/22,  Garrick)  reports  San  Diego  may  "take  a  key  step  Tuesday  toward  more  rigorous  police 
oversight,  transparency  and  accountability."  The  San  Diego  City  Council  "is  scheduled  to  evaluate  a  proposed  November  ballot 
measure  that  would  create  a  police  review  board  with  the  power  to  launch  independent  misconduct  investigations  and 
subpoena  witnesses.  While  the  proposal  has  been  in  the  works  for  several  years,  it  gained  momentum  in  the  wake  of  recent 
local  and  national  police  protests  that  have  sparked  calls  for  fundamental  law  enforcement  reforms."  The  city  "completed 
negotiations  May  21  with  the  labor  union  representing  police  officers  on  the  proposed  ballot  measure,  which  would  let  officers 
appeal  declarations  by  the  commission  that  they  are  guilty  of  misconduct." 


Join  the  IACP  on  June  24,  2020,  at  1:00  p.m.  EST  for  Part  2  and  July  16,  2020,  at  1:00  p.m.  EST  for  Part  3  of 
Mindfulness  Strategies  for  Law  Enforcement  webinar  series.  This  webinar  is  part  of  the  U.S.  Department  of 
Justice,  Bureau  of  Justice  Assistance's  National  Officer  Safety  Initiatives  Program  and  will  be  hosted  by  Mindful 
Junkie  Founder,  Gina  White.  Police  officers  across  every  rank,  dispatchers,  victim  services  personnel,  crime  scene 
personnel,  other  law  enforcement  personnel  and  family  members  are  encouraged  to  attend  these  30-minute 
interactive  mindfulness  sessions. 

Reserve  you  space. 


Connect  with  the  IACP 
online: 


IACP  Event  Calendar: 


CRIME  &  DRUGS 


Swedish  Rape  Conviction  Rates  Rise  75%  After  Change  In  Law 

Reuters  (6/22,  Batha)  reports,  "Rape  conviction  rates  in  Sweden  have  risen  75%  in  two  years  following  a  major  change  in 
the  law,  spurring  calls  on  Monday  for  other  countries  to  revamp  their  legislation."  Reuters  adds,  "Sweden  changed  the  legal 
definition  of  rape  in  2018  to  sex  without  consent.  Unlike  in  many  countries,  prosecutors  do  not  have  to  prove  the  use  or  threat 
of  violence  or  coercion.  The  National  Council  on  Crime  Prevention  (Bra)  said  the  rise  in  convictions  -  up  from  190  in  2017  to  333 
in  2019  -  showed  the  change  had  had  a  greater  impact  than  expected."  According  to  Reuters,  "Britain,  Belgium,  Canada, 

Cyprus,  Germany,  Greece,  Iceland,  Ireland  and  Luxembourg  already  define  rape  as  sex  without  consent,  while  Denmark, 

Finland,  Spain  and  Portugal  have  promised  similar  reforms." 

New  York  City  Raid  Leads  To  Drug  Seizures,  Two  Arrests 

The  New  York  Post  (6/22,  Rosenberg)  reports  a  recent  raid  of  a  suspected  pill  mill  in  New  York  City  led  to  the  seizure  of 
"approximately  1.2  kilograms  of  heroin,  34  grams  of  fentanyl  and  2.3  kilograms  of  methamphetamine."  Arrested  in  connection 
with  the  raid  were  Jeison  Lebron  and  Alfredo  Goris,  who  face  "charges  of  criminal  possession  of  a  controlled  substance  and 
criminally  using  drug  paraphernalia."  The  arrests  were  the  result  of  joint  operation  conducted  by  "the  city's  Special  Narcotics 
Prosecutor,"  the  City  of  New  York  Police  Department,  and  the  DEA. 

UK  Drinkers  Barricade  Themselves  In  Pub  During  Illegal  Lockdown  Lock-In 

The  Independent  (UK)  (6/22,  Gregory)  reports,  "Drinkers  at  an  illegal  lockdown-defying  lock-in  have  barricaded 
themselves  in  a  pub  after  police  officers  arrived  to  break  up  the  session,  according  to  police."  According  to  the  Independent, 
"Merseyside  Police  officers  were  pelted  with  beer  and  other  items  as  revellers  took  up  their  fortified  position  at  the  Britannia 
Hotel  pub  in  Liverpool,  the  force  said.  There  were  reportedly  more  than  100  people  gathered  at  the  Vauxhall  pub  at  around 
midnight  on  Sunday,  playing  loud  music  and  disturbing  residents  nearby,  although  only  'a  number  of  people'  were  said  to  take 
part  in  the  blockade."  The  Independent  adds,  "Seven  men  and  one  woman,  aged  between  21  and  33,  were  arrested  for  violent 
disorder  and  drugs  offences.  Pubs  have  been  closed  by  law  for  the  last  three  months  to  fight  the  spread  of  coronavirus,  with 
Boris  Johnson  expected  to  allow  them  to  re-open  on  4  July,  albeit  with  a  range  of  new  measures  in  place  to  protect  customers." 

TECHNOLOGY 


"Blueleaks"  Hackers  Release  "Hundreds  Of  Thousands"  Of  Private  Records  On  Officers 

The  Blaze  (6/22,  Taylor)  reports  hackers  have  "leaked  highly  sensitive  police  files  from  over  200  police  departments  across 
the  country."  Activist  group  DDoSecrets  "published  what  the  outlet  calls  'hundreds  of  gigabytes'  worth  of  potentially  sensitive 
files'  from  police  departments  across  the  US."  The  group  has  "called  the  information  dump  'BlueLeaks.'"  The  group  "compiled 
the  records,  disseminating  them  into  a  searchable  database  that  can  pull  up  private  information  from  a  police  badge  number." 
Many  of  the  files  include  "information  such  as  memos,  emails,  and  officers'  personal  information".  The  group  "shared 
information  on  Twitter  regarding  the  data  dump." 


GLOBAL  SECURITY 


NYTimes  Analysis:  Antifa  Rumors  Show  Ways  Information  Spreads  Locally 

The  New  York  Times  (6/22,  Alba,  Decker)  examines  how  in  recent  weeks,  "residents  in  at  least  41  U.S.  cities  and  towns 
became  alarmed  by  rumors  that  the  loose  collective  of  anti-fascist  activists  known  as  antifa  was  headed  to  their  area,  according 
to  an  analysis  by  The  New  York  Times.  In  many  cases,  they  contacted  their  local  law  enforcement  for  help.  In  each  case,  it  was 
for  a  threat  that  never  appeared."  On  the  local  level,  the  analysis  found  that  "the  source  of  the  false  information  has  usually 
been  more  subtle,  and  shows  the  complexity  of  stunting  misinformation  online.  The  bad  information  often  first  appears  in  a 
Twitter  or  Facebook  post,  or  a  YouTube  video  there.  It  is  then  shared  on  online  spaces  like  local  Facebook  groups,  the 
neighborhood  social  networking  app  Nextdoor  and  community  texting  networks,"  which  "can  fall  under  the  radar  of  the  tech 
companies  and  online  fact  checkers." 

Black  Lives  Matter  Protests  Spread  To  White,  Rural  Areas.  The  Wall  Street  Journal  ^H(6/22,  Carlton,  Subscription 
Publication)  reports  that  the  protests  for  racial  justice  have  quickly  spread  from  big  cities  to  small,  rural  towns  that  are 
predominantly  white. 
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RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


To: 

Sent: 

Received: 


Douglas  Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov> 
June  23,  2020  6:44:57  AM  CDT 
June  23,  2020  6:44:53  AM  CDT 


1. 


From:  Douglas  Maclean  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:26  AM 

To:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov>;  Amar  Patel  (Sheriff) 
<Amar.Patel@cookcountyil.gov>;  Adnan  Memon  (Sheriff)  <Adnan.Memon@cookcountyil.gov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


Keith  - 


Doug 


From:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

Sent:  Tuesday,  June  23,  2020  6:20  AM 

To:  Douglas  Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov>:  Amar  Patel  (Sheriff) 
<Amar.Patel@cookcountyil.gov>:  Adnan  Memon  (Sheriff)  <Adnan.Memon@cookcountyil.gov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Deputy  CIO  Maclean, 


Thanks, 


Morrison 


From:  Douglas  Maclean  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:10  AM 

To:  Amar  Patel  (Sheriff)  <Amar. Patel@cookcountyil.gov>:  Keith  Morrison  (Sheriff) 

<Keith. Morrison@cookcountyil.gov>:  Adnan  Memon  (Sheriff)  <Adnan. Memon@cookcountyil.gov> 

Subject:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Krebs  on  Security  reports  Blue  Leaks  has  posted  24  years  of  LEA  and  fusion  center-related  data  as  the  result  of  a 
breach  on  Netsential,  an  internet  services  provider  to  LEAs  and  operational  fusion  centers.  The  data  includes  some 
information  related  to  sensitive  operations  and  a  significant  amount  of  Pll. 

The  Krebs  on  Security  story  can  be  found  here 


Keith  -  do  we  have  any  exposure  from  this  breach  either  directly  from  our  own  infrastructure  or  indirectly  as  the 
result  of  data-sharing  with  other  agencies?  Do  any  of  our  vendors  use  or  have  they  used  Netsential  for  any  of  their 
operations  from  1994  to  present? 


Douglas  MacLean 
Deputy  CIO 

Cook  County  Sheriffs  Office 
3026  S.  California 
South  Campus  Building  1 
Chicago  IL  60608 
312.877.2048  [c] 
773.674.8615  [d] 


RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


From:  Keith  Morrison  (Sheriff)  </0=EXCHANGELABS/OU=EXCHANGE  ADMINISTRATIVE 

GROUP 

(FYDIBOHF23SPDLT)/CN=RECIPIENTS/CN=D2EBEC5431A14B10A53942341  DBD54F 
4-KEITH  MORRI> 

To:  Douglas  Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov> 

Sent:  June  23,  2020  6:45:1 1  AM  CDT 


Received:  June  23,  2020  6:45:00  AM  CDT 


From:  Douglas  Maclean  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:26  AM 

To:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov>;  Amar  Patel  (Sheriff) 
<Amar.Patel@cookcountyil.gov>;  Adnan  Memon  (Sheriff)  <Adnan. Memon@cookcountyil.gov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Keith  - 


Doug 

From:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

Sent:  Tuesday,  June  23,  2020  6:20  AM 

To:  Douglas  Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov>:  Amar  Patel  (Sheriff) 
<Amar.Patel@cookcountyil.gov>:  Adnan  Memon  (Sheriff)  <Adnan.Memon@cookcountyil.gov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Deputy  CIO  Maclean, 


Thanks, 

Morrison 


From:  Douglas  Maclean  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:10  AM 

To:  Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov>:  Keith  Morrison  (Sheriff) 
<Keith.Morrison@cookcountyil.gov>;  Adnan  Memon  (Sheriff)  <Adnan.Memon@cookcountyil.gov> 

Subject:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Krebs  on  Security  reports  Blue  Leaks  has  posted  24  years  of  LEA  and  fusion  center-related  data  as  the  result  of  a 
breach  on  Netsential,  an  internet  services  provider  to  LEAs  and  operational  fusion  centers.  The  data  includes  some 
information  related  to  sensitive  operations  and  a  significant  amount  of  Pll. 

The  Krebs  on  Security  story  can  be  found  here 


Keith  -  do  we  have  any  exposure  from  this  breach  either  directly  from  our  own  infrastructure  or  indirectly  as  the 
result  of  data-sharing  with  other  agencies?  Do  any  of  our  vendors  use  or  have  they  used  Netsential  for  any  of  their 
operations  from  1994  to  present? 


Douglas  MacLean 
Deputy  CIO 

Cook  County  Sheriffs  Office 
3026  S.  California 
South  Campus  Building  1 
Chicago  IL  60608 
312.877.2048  [c] 
773.674.8615  [d] 


FW:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


From:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

To:  Christopher  Moore  (Sheriff)  <Christopher.Moore@cookcountyil.gov> 

Sent:  June  23,  2020  6:45:25  AM  CDT 

Received:  June  23,  2020  6:45:25  AM  CDT 


From:  Keith  Morrison  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:45  AM 

To:  Douglas  Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


From:  Douglas  Maclean  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:26  AM 

To:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov>;  Amar  Patel  (Sheriff) 
<Amar.Patel@cookcountyil.gov>;  Adnan  Memon  (Sheriff)  <Adnan.Memon(5)cookcountvil.gov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Keith  - 


Doug 

From:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

Sent:  Tuesday,  June  23,  2020  6:20  AM 

To:  Douglas  Maclean  (Sheriff)  <Douglas.Maclean2@cookcountvil.gov>;  Amar  Patel  (Sheriff) 
<Amar.Patel@cookcountyil.gov>;  Adnan  Memon  (Sheriff)  <Adnan. Memon@cookcountvil.gov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Deputy  CIO  Maclean, 


Thanks, 

Morrison 


From:  Douglas  Maclean  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:10  AM 

To:  Amar  Patel  (Sheriff)  <Amar. Patel@cookcountvil.gov>;  Keith  Morrison  (Sheriff) 

<Keith. Morrison@cookcountvil.gov>;  Adnan  Memon  (Sheriff)  <Adnan. Memon@cookcountyil.gov> 
Subject:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


Krebs  on  Security  reports  Blue  Leaks  has  posted  24  years  of  LEA  and  fusion  center-related  data  as  the  result  of  a 
breach  on  Netsential,  an  internet  services  provider  to  LEAs  and  operational  fusion  centers.  The  data  includes  some 
information  related  to  sensitive  operations  and  a  significant  amount  of  Pll. 

The  Krebs  on  Security  story  can  be  found  here 

Keith  -  do  we  have  any  exposure  from  this  breach  either  directly  from  our  own  infrastructure  or  indirectly  as  the 
result  of  data-sharing  with  other  agencies?  Do  any  of  our  vendors  use  or  have  they  used  Netsential  for  any  of  their 
operations  from  1994  to  present? 


Douglas  MacLean 
Deputy  CIO 

Cook  County  Sheriffs  Office 
3026  S.  California 
South  Campus  Building  1 
Chicago  IL  60608 
312.877.2048  [c] 
773.674.8615  [d] 


FW:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


From:  Keith  Morrison  (Sheriff)  </0=EXCHANGELABS/OU=EXCHANGE  ADMINISTRATIVE 

GROUP 

(FYDIBOHF23SPDLT)/CN=RECIPIENTS/CN=D2EBEC5431A14B10A53942341  DBD54F 
4-KEITH  MORRI> 

To:  Christopher  Moore  (Sheriff)  <Christopher.Moore@cookcountyil.gov> 

Sent:  June  23,  2020  6:45:25  AM  CDT 

Received:  June  23,  2020  6:45:00  AM  CDT 


From:  Keith  Morrison  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:45  AM 

To:  Douglas  Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


From:  Douglas  Maclean  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:26  AM 

To:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov>:  Amar  Patel  (Sheriff) 
<Amar.Patel@cookcountyil.gov>:  Adnan  Memon  (Sheriff)  <Adnan.Memon@cookcountyil.gov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Keith  - 


Doug 

From:  Keith  Morrison  (Sheriff)  <Keith. Morrison@cookcountvil.gov> 

Sent:  Tuesday,  June  23,  2020  6:20  AM 

To:  Douglas  Maclean  (Sheriff)  <Douglas. Maclean2@cookcountvil.gov>:  Amar  Patel  (Sheriff) 
<Amar. Patel@cookcountvil.gov>:  Adnan  Memon  (Sheriff)  <Adnan. Memon@cookcountvil.gov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Deputy  CIO  Maclean, 


Thanks, 

Morrison 


From:  Douglas  Maclean  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:10  AM 

To:  Amar  Patel  (Sheriff)  <Amar. Patel@cookcountvil.gov>:  Keith  Morrison  (Sheriff) 
<Keith.Morrison@cookcountyil.gov>:  Adnan  Memon  (Sheriff)  <Adnan.Memon@cookcountyil.gov> 
Subject:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


Krebs  on  Security  reports  Blue  Leaks  has  posted  24  years  of  LEA  and  fusion  center-related  data  as  the  result  of  a 
breach  on  Netsential,  an  internet  services  provider  to  LEAs  and  operational  fusion  centers.  The  data  includes  some 
information  related  to  sensitive  operations  and  a  significant  amount  of  Pll. 

The  Krebs  on  Security  story  can  be  found  here 

Keith  -  do  we  have  any  exposure  from  this  breach  either  directly  from  our  own  infrastructure  or  indirectly  as  the 
result  of  data-sharing  with  other  agencies?  Do  any  of  our  vendors  use  or  have  they  used  Netsential  for  any  of  their 
operations  from  1994  to  present? 


Douglas  MacLean 
Deputy  CIO 

Cook  County  Sheriffs  Office 
3026  S.  California 
South  Campus  Building  1 
Chicago  IL  60608 
312.877.2048  [c] 
773.674.8615  [d] 


FW:  lACP's  The  Lead:  Massachusetts  Governor  Seeks  Training  Bonuses  For 
Police  Officers 


From:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

To:  Kevin  O'Donnell  (Sheriff)  <Kevin. Odonnell@cookcountyil.gov> 

Sent:  June  23,  2020  6:52:01  AM  CDT 

Received:  June  23,  2020  6:52:02  AM  CDT 


From:  The  IACP  [mailto:TheLead@iacp.bulletinmedia.com] 

Sent:  Tuesday,  June  23,  2020  6:43  AM 

To:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

Subject:  lACP's  The  Lead:  US  Supreme  Court  Will  Not  Revisit  Challenge  To  Qualified  Immunity  For  Police. 
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POLICING  &  POLICY 


US  Supreme  Court  Will  Not  Revisit  Challenge  To  Qualified  Immu 
Police 

ABC  News  (6/22,  Dwyer)  reports,  "The  U.S.  Supreme  Court  on  Monday  off 
a  pass  on  revisiting  its  50-year-old  doctrine  of  'qualified  immunity'  for  law  enforc 
officers,  despite  intense  national  outcry  over  police  misconduct  and  legal  protect 
shield  cops  from  liability.  'The  Supreme  Court  has  made  clear  that  they  are  not  pi 
reconsider  qualified  immunity  at  this  moment,'  said  Joanna  Schwartz,  an  expert  c 
doctrine  at  UCLA  School  of  Law."  ABC  News  adds,  "While  the  Civil  Rights  Act  of  1! 
Americans  the  unambiguous  ability  to  sue  public  officials  over  civil  rights  violatioi 
Supreme  Court  subsequently  limited  liability  to  only  those  rights  that  have  becon 
established  law.'" 

Newsdav  (NY)  (6/22,  Brune)  reports  that  qualified  immunity  "shields  | 

from  being  sued  for  money  damages  in  federal  court  for  constitutional  violations 
excessive  force  unless  the  officers  broke  any  'clearly  established'  law  -  a  high  bar 
plaintiffs  to  overcome."  Newsday  adds  that  police  groups  argue  that  ending  quali 
would  have  a  chilling  effect  on  police  work,  make  them  hesitant  to  act  when  they  should  be  decisive  in  dicey  situations,  or  lead  to  retiremer 
dI  of  applicants  for  police  jobs.  'Qualified  immunity  is  a  foundational  protection  for  the  policing  profession  and  any  modification  to  this  legal 
devastating  impact  on  the  police's  ability  to  fulfill  its  public  safety  mission,'  the  International  Association  of  Chiefs  of  Police  said  in  a  stateme 

lemocrats  Threaten  To  Block  GOP  Police  Reform  Bill 

(6/22,  Everett,  Levine)  reports  Senate  Democrats  are  "strongly  signaling  they  will  filibuster  Republicans'  police  reform  bill  later  this  weel 
assions"  from  Senate  Majority  Leader  McConnell,  who  "set  the  Senate  on  a  path  to  consider  the  legislation  on  Wednesday."  Sen.  Jon  Tester 
thing  changes,  I'm  voting  no.  I  need  some  assurances  that  we're  going  to  vote  on  amendments  that  will  fix  this  bill.  And  it  needs  a  lot  of  fixin 
?ader  Schumer  called  the  GOP  bill  "deeply  and  fundamentally  flawed." 

rs  Analysis:  Neither  Senate  Nor  House  Police  Reform  Bill  Likely  To  Become  Law.  Reuters  (6/22,  Morgan)  reports  that  the  Sen 
"will  vote  this  week  on  separate  bills  aimed  at  addressing  police  misconduct.. .but  neither  measure  is  likely  to  become  law."  The  Senate  "is  e 
:edural  vote  on  a  Republican  bill  by  Wednesday,  while  the  House  is  due  to  vote  on  more  sweeping  Democratic  legislation  on  Thursday."  How 
/s,  "neither  measure,  as  written,  appears  to  have  enough  bipartisan  support  to  win  approval  from  both  chambers  and  be  signed  into  law." 

ind  Recreational  Marijuana  Laws  May  Boost  Traffic  Deaths 

(6/22,  Tanner)  reports,  "Laws  legalizing  recreational  marijuana  may  lead  to  more  traffic  deaths,  two  new  studies  suggest,  although  ques 
>ut  how  they  might  influence  driving  habits."  According  to  the  AP,  "Previous  research  has  had  mixed  results  and  the  new  studies,  published  I 
nal  Medicine,  can't  prove  that  the  traffic  death  increases  they  found  were  caused  by  marijuana  use."  The  AP  adds,  "One  study  found  an  exc 
hs  per  year  after  retail  sales  began  in  Colorado  in  January  2014,  compared  with  states  without  similar  laws,"  but  "it  found  no  similar  change 
n  state."  The  other  study  "looked  at  those  states  plus  two  others  that  allow  recreational  pot  sales,  Oregon  and  Alaska.  If  every  state  legalize! 
si  marijuana  sales,  an  extra  6,800  people  would  die  each  year  in  traffic  accidents,  the  researchers  calculated." 

c  Has  Increased  New  York  City  Criminal  Court  Backlog  To  More  Than  39K  Cases 

ark  Times  (6/22,  Al,  Feuer,  Hong,  Weiser,  Ransom)  has  a  2,400-word  report  on  what  it  calls  New  York  City's  "legal  limbo,"  where  "the 

cases  in  the  city's  criminal  courts  has  risen  by  nearly  a  third"  to  39,200  due  to  the  coronavirus  pandemic.  The  Times  says  "hundreds  of  jury  t 
een  put  on  hold  indefinitely,"  and  "arraignments,  pleas  and  evidentiary  hearings  are  being  held  by  video,  with  little  public  scrutiny." 

usetts  Governor  Seeks  Training  Bonuses  For  Police  Officers 

(6/22,  Gavin)  reports,  "Police  officers  in  Massachusetts  could  receive  one-time  bonuses  of  up  to  $5,000  should  they  take  on  additional  ti 
I  filed  last  week  by  Gov.  Charlie  Baker  centered  on  creating  a  police  certification  system."  According  to  Boston,  "The  vision  is  to  incentivize  o 
the  necessary  minimum  training  laid  out  in  the  sweeping  proposal,  which  comes  amid  the  nationwide  movement  to  reduce  funding  for  law 
nt,  and  instead  funnel  resources  into  other  initiatives  such  as  anti-violence  and  public  health  programs."  The  bill,  "which  seeks  to  establish  a 


:ertify,  and  de-certify,  police  officers/'  would  "provide  financial  opportunity  to  officers  to  advance  their  training  in  key  areas,  including  first  a 
tactics,  and  narcoticstraining." 

o,  California  Ballot  Measure  Would  Reform  Police  Oversight,  Accountability 

ggo  Union-Tribune  (6/22,  Garrick)  reports  San  Diego  may  "take  a  key  step  Tuesday  toward  more  rigorous  police  oversight,  transparer 
lity."  The  San  Diego  City  Council  "is  scheduled  to  evaluate  a  proposed  November  ballot  measure  that  would  create  a  police  review  board  wii 
lunch  independent  misconduct  investigations  and  subpoena  witnesses.  While  the  proposal  has  been  in  the  works  for  several  years,  it  gained 
n  in  the  wake  of  recent  local  and  national  police  protests  that  have  sparked  calls  for  fundamental  law  enforcement  reforms."  The  city  "comp 
is  May  21  with  the  labor  union  representing  police  officers  on  the  proposed  ballot  measure,  which  would  let  officers  appeal  declarations  by 
n  that  they  are  guilty  of  misconduct." 


IACP  on  June  24,  2020,  at  1:00  p.m.  EST  for  Part  2  and  July  16,  2020,  at  1:00  p.m.  EST  for  Part  3  of  Mindfulness  Strategies  for  Lav 
nent  webinar  series.  This  webinar  is  part  of  the  U.S.  Department  of  Justice,  Bureau  of  Justice  Assistance's  National  Officer  Safety 
is  Program  and  will  be  hosted  by  Mindful  Junkie  Founder,  Gina  White.  Police  officers  across  every  rank,  dispatchers,  victim  servii 
el,  crime  scene  personnel,  other  law  enforcement  personnel  and  family  members  are  encouraged  to  attend  these  30-minute 
ve  mindfulness  sessions. 

you  space. 
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Rape  Conviction  Rates  Rise  75%  After  Change  In  Law 

(6/22,  Batha)  reports,  "Rape  conviction  rates  in  Sweden  have  risen  75%  in  two  years  following  a  major  change  in  the  law,  spurring  calls 
r  other  countries  to  revamp  their  legislation."  Reuters  adds,  "Sweden  changed  the  legal  definition  of  rape  in  2018  to  sex  without  consent.  Ui 
tries,  prosecutors  do  not  have  to  prove  the  use  or  threat  of  violence  or  coercion.  The  National  Council  on  Crime  Prevention  (Bra)  said  the  ris 
;  -  up  from  190  in  2017  to  333  in  2019  -  showed  the  change  had  had  a  greater  impact  than  expected."  According  to  Reuters,  "Britain,  Belgiu 
prus,  Germany,  Greece,  Iceland,  Ireland  and  Luxembourg  already  define  rape  as  sex  without  consent,  while  Denmark,  Finland,  Spain  and  Poi 
ised  similar  reforms." 

k  City  Raid  Leads  To  Drug  Seizures,  Two  Arrests 

ark  Post  (6/22,  Rosenberg)  reports  a  recent  raid  of  a  suspected  pill  mill  in  New  York  City  led  to  the  seizure  of  "approximately  1.2  kilog 
grams  of  fentanyl  and  2.3  kilograms  of  methamphetamine."  Arrested  in  connection  with  the  raid  were  Jeison  Lebron  and  Alfredo  Goris,  who 
F  criminal  possession  of  a  controlled  substance  and  criminally  using  drug  paraphernalia."  The  arrests  were  the  result  of  joint  operation  condi 
special  Narcotics  Prosecutor,"  the  City  of  New  York  Police  Department,  and  the  DEA. 

ers  Barricade  Themselves  In  Pub  During  Illegal  Lockdown  Lock-In 

indent  (UK)  (6/22,  Gregory)  reports,  "Drinkers  at  an  illegal  lockdown-defying  lock-in  have  barricaded  themselves  in  a  pub  after  police 

jreak  up  the  session,  according  to  police."  According  to  the  Independent,  "Merseyside  Police  officers  were  pelted  with  beer  and  other  items 
iok  up  their  fortified  position  at  the  Britannia  Hotel  pub  in  Liverpool,  the  force  said.  There  were  reportedly  more  than  100  people  gathered  z 
jb  at  around  midnight  on  Sunday,  playing  loud  music  and  disturbing  residents  nearby,  although  only  'a  number  of  people'  were  said  to  take 
The  Independent  adds,  "Seven  men  and  one  woman,  aged  between  21  and  33,  were  arrested  for  violent  disorder  and  drugs  offences.  Pubs 


aw  for  the  last  three  months  to  fight  the  spread  of  coronavirus,  with  Boris  Johnson  expected  to  allow  them  to  re-open  on  4  July,  albeit  with  ; 
ires  in  place  to  protect  customers." 

IOLOGY 


ks"  Hackers  Release  "Hundreds  Of  Thousands"  Of  Private  Records  On  Officers 

(6/22,  Taylor)  reports  hackers  have  "leaked  highly  sensitive  police  files  from  over  200  police  departments  across  the  country."  Activist 
a  "published  what  the  outlet  calls  'hundreds  of  gigabytes'  worth  of  potentially  sensitive  files'  from  police  departments  across  the  US."  The  gr 
information  dump  'BlueLeaks.'"  The  group  "compiled  the  records,  disseminating  them  into  a  searchable  database  that  can  pull  up  private  ir 
ce  badge  number."  Many  of  the  files  include  "information  such  as  memos,  emails,  and  officers'  personal  information".  The  group  "shared  in 
regarding  the  data  dump." 

VL  SECURITY 


Analysis:  Antifa  Rumors  Show  Ways  Information  Spreads  Locally 

ark  Times  (6/22,  Alba,  Decker)  examines  how  in  recent  weeks,  "residents  in  at  least  41  U.S.  cities  and  towns  became  alarmed  by  rum< 

ollective  of  anti-fascist  activists  known  as  antifa  was  headed  to  their  area,  according  to  an  analysis  by  The  New  York  Times.  In  many  cases,  th 
their  local  law  enforcement  for  help.  In  each  case,  it  was  for  a  threat  that  never  appeared."  On  the  local  level,  the  analysis  found  that  "the  sc 
formation  has  usually  been  more  subtle,  and  shows  the  complexity  of  stunting  misinformation  online.  The  bad  information  often  first  appea 
:acebook  post,  or  a  YouTube  video  there.  It  is  then  shared  on  online  spaces  like  local  Facebook  groups,  the  neighborhood  social  networking 
nd  community  texting  networks,"  which  "can  fall  under  the  radar  of  the  tech  companies  and  online  fact  checkers." 

Lives  Matter  Protests  Spread  To  White,  Rural  Areas.  The  Wall  Street  Journal  (6/22,  Carlton,  Subscription  Publication)  reports  tf 

r  racial  justice  have  quickly  spread  from  big  cities  to  small,  rural  towns  that  are  predominantly  white. 
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FW:  lACP's  The  Lead:  Massachusetts  Governor  Seeks  Training  Bonuses  For 
Police  Officers 
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Subject:  lACP's  The  Lead:  US  Supreme  Court  Will  Not  Revisit  Challenge  To  Qualified  Immunity  For  Police. 
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US  Supreme  Court  Will  Not  Revisit  Challenge  To  Qualified  Immu 
Police 

ABC  News  (6/22,  Dwyer)  reports,  "The  U.S.  Supreme  Court  on  Monday  off 
a  pass  on  revisiting  its  50-year-old  doctrine  of  'qualified  immunity'  for  law  enforc 
officers,  despite  intense  national  outcry  over  police  misconduct  and  legal  protect 
shield  cops  from  liability.  'The  Supreme  Court  has  made  clear  that  they  are  not  pi 
reconsider  qualified  immunity  at  this  moment,'  said  Joanna  Schwartz,  an  expert  c 
doctrine  at  UCLA  School  of  Law."  ABC  News  adds,  "While  the  Civil  Rights  Act  of  1! 
Americans  the  unambiguous  ability  to  sue  public  officials  over  civil  rights  violatioi 
Supreme  Court  subsequently  limited  liability  to  only  those  rights  that  have  becon 
established  law.'" 

Newsdav  (NY)  (6/22,  Brune)  reports  that  qualified  immunity  "shields  | 

from  being  sued  for  money  damages  in  federal  court  for  constitutional  violations 
excessive  force  unless  the  officers  broke  any  'clearly  established'  law  -  a  high  bar 
plaintiffs  to  overcome."  Newsday  adds  that  police  groups  argue  that  ending  quali 
would  have  a  chilling  effect  on  police  work,  make  them  hesitant  to  act  when  they  should  be  decisive  in  dicey  situations,  or  lead  to  retiremer 
dI  of  applicants  for  police  jobs.  'Qualified  immunity  is  a  foundational  protection  for  the  policing  profession  and  any  modification  to  this  legal 
devastating  impact  on  the  police's  ability  to  fulfill  its  public  safety  mission,'  the  International  Association  of  Chiefs  of  Police  said  in  a  stateme 

lemocrats  Threaten  To  Block  GOP  Police  Reform  Bill 

(6/22,  Everett,  Levine)  reports  Senate  Democrats  are  "strongly  signaling  they  will  filibuster  Republicans'  police  reform  bill  later  this  weel 
assions"  from  Senate  Majority  Leader  McConnell,  who  "set  the  Senate  on  a  path  to  consider  the  legislation  on  Wednesday."  Sen.  Jon  Tester 
thing  changes,  I'm  voting  no.  I  need  some  assurances  that  we're  going  to  vote  on  amendments  that  will  fix  this  bill.  And  it  needs  a  lot  of  fixin 
?ader  Schumer  called  the  GOP  bill  "deeply  and  fundamentally  flawed." 

rs  Analysis:  Neither  Senate  Nor  House  Police  Reform  Bill  Likely  To  Become  Law.  Reuters  (6/22,  Morgan)  reports  that  the  Sen 
"will  vote  this  week  on  separate  bills  aimed  at  addressing  police  misconduct.. .but  neither  measure  is  likely  to  become  law."  The  Senate  "is  e 
:edural  vote  on  a  Republican  bill  by  Wednesday,  while  the  House  is  due  to  vote  on  more  sweeping  Democratic  legislation  on  Thursday."  How 
/s,  "neither  measure,  as  written,  appears  to  have  enough  bipartisan  support  to  win  approval  from  both  chambers  and  be  signed  into  law." 

ind  Recreational  Marijuana  Laws  May  Boost  Traffic  Deaths 

(6/22,  Tanner)  reports,  "Laws  legalizing  recreational  marijuana  may  lead  to  more  traffic  deaths,  two  new  studies  suggest,  although  ques 
>ut  how  they  might  influence  driving  habits."  According  to  the  AP,  "Previous  research  has  had  mixed  results  and  the  new  studies,  published  I 
nal  Medicine,  can't  prove  that  the  traffic  death  increases  they  found  were  caused  by  marijuana  use."  The  AP  adds,  "One  study  found  an  exc 
hs  per  year  after  retail  sales  began  in  Colorado  in  January  2014,  compared  with  states  without  similar  laws,"  but  "it  found  no  similar  change 
n  state."  The  other  study  "looked  at  those  states  plus  two  others  that  allow  recreational  pot  sales,  Oregon  and  Alaska.  If  every  state  legalize! 
si  marijuana  sales,  an  extra  6,800  people  would  die  each  year  in  traffic  accidents,  the  researchers  calculated." 

c  Has  Increased  New  York  City  Criminal  Court  Backlog  To  More  Than  39K  Cases 

ark  Times  (6/22,  Al,  Feuer,  Hong,  Weiser,  Ransom)  has  a  2,400-word  report  on  what  it  calls  New  York  City's  "legal  limbo,"  where  "the 

cases  in  the  city's  criminal  courts  has  risen  by  nearly  a  third"  to  39,200  due  to  the  coronavirus  pandemic.  The  Times  says  "hundreds  of  jury  t 
een  put  on  hold  indefinitely,"  and  "arraignments,  pleas  and  evidentiary  hearings  are  being  held  by  video,  with  little  public  scrutiny." 

usetts  Governor  Seeks  Training  Bonuses  For  Police  Officers 

(6/22,  Gavin)  reports,  "Police  officers  in  Massachusetts  could  receive  one-time  bonuses  of  up  to  $5,000  should  they  take  on  additional  ti 
I  filed  last  week  by  Gov.  Charlie  Baker  centered  on  creating  a  police  certification  system."  According  to  Boston,  "The  vision  is  to  incentivize  o 
the  necessary  minimum  training  laid  out  in  the  sweeping  proposal,  which  comes  amid  the  nationwide  movement  to  reduce  funding  for  law 
nt,  and  instead  funnel  resources  into  other  initiatives  such  as  anti-violence  and  public  health  programs."  The  bill,  "which  seeks  to  establish  a 


:ertify,  and  de-certify,  police  officers/'  would  "provide  financial  opportunity  to  officers  to  advance  their  training  in  key  areas,  including  first  a 
tactics,  and  narcoticstraining." 

o,  California  Ballot  Measure  Would  Reform  Police  Oversight,  Accountability 

ggo  Union-Tribune  (6/22,  Garrick)  reports  San  Diego  may  "take  a  key  step  Tuesday  toward  more  rigorous  police  oversight,  transparer 
lity."  The  San  Diego  City  Council  "is  scheduled  to  evaluate  a  proposed  November  ballot  measure  that  would  create  a  police  review  board  wii 
lunch  independent  misconduct  investigations  and  subpoena  witnesses.  While  the  proposal  has  been  in  the  works  for  several  years,  it  gained 
n  in  the  wake  of  recent  local  and  national  police  protests  that  have  sparked  calls  for  fundamental  law  enforcement  reforms."  The  city  "comp 
is  May  21  with  the  labor  union  representing  police  officers  on  the  proposed  ballot  measure,  which  would  let  officers  appeal  declarations  by 
n  that  they  are  guilty  of  misconduct." 


IACP  on  June  24,  2020,  at  1:00  p.m.  EST  for  Part  2  and  July  16,  2020,  at  1:00  p.m.  EST  for  Part  3  of  Mindfulness  Strategies  for  Lav 
nent  webinar  series.  This  webinar  is  part  of  the  U.S.  Department  of  Justice,  Bureau  of  Justice  Assistance's  National  Officer  Safety 
is  Program  and  will  be  hosted  by  Mindful  Junkie  Founder,  Gina  White.  Police  officers  across  every  rank,  dispatchers,  victim  servii 
el,  crime  scene  personnel,  other  law  enforcement  personnel  and  family  members  are  encouraged  to  attend  these  30-minute 
ve  mindfulness  sessions. 

you  space. 
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Rape  Conviction  Rates  Rise  75%  After  Change  In  Law 

(6/22,  Batha)  reports,  "Rape  conviction  rates  in  Sweden  have  risen  75%  in  two  years  following  a  major  change  in  the  law,  spurring  calls 
r  other  countries  to  revamp  their  legislation."  Reuters  adds,  "Sweden  changed  the  legal  definition  of  rape  in  2018  to  sex  without  consent.  Ui 
tries,  prosecutors  do  not  have  to  prove  the  use  or  threat  of  violence  or  coercion.  The  National  Council  on  Crime  Prevention  (Bra)  said  the  ris 
;  -  up  from  190  in  2017  to  333  in  2019  -  showed  the  change  had  had  a  greater  impact  than  expected."  According  to  Reuters,  "Britain,  Belgiu 
prus,  Germany,  Greece,  Iceland,  Ireland  and  Luxembourg  already  define  rape  as  sex  without  consent,  while  Denmark,  Finland,  Spain  and  Poi 
ised  similar  reforms." 

k  City  Raid  Leads  To  Drug  Seizures,  Two  Arrests 

ark  Post  (6/22,  Rosenberg)  reports  a  recent  raid  of  a  suspected  pill  mill  in  New  York  City  led  to  the  seizure  of  "approximately  1.2  kilog 
grams  of  fentanyl  and  2.3  kilograms  of  methamphetamine."  Arrested  in  connection  with  the  raid  were  Jeison  Lebron  and  Alfredo  Goris,  who 
F  criminal  possession  of  a  controlled  substance  and  criminally  using  drug  paraphernalia."  The  arrests  were  the  result  of  joint  operation  condi 
special  Narcotics  Prosecutor,"  the  City  of  New  York  Police  Department,  and  the  DEA. 

ers  Barricade  Themselves  In  Pub  During  Illegal  Lockdown  Lock-In 

indent  (UK)  (6/22,  Gregory)  reports,  "Drinkers  at  an  illegal  lockdown-defying  lock-in  have  barricaded  themselves  in  a  pub  after  police 

jreak  up  the  session,  according  to  police."  According  to  the  Independent,  "Merseyside  Police  officers  were  pelted  with  beer  and  other  items 
iok  up  their  fortified  position  at  the  Britannia  Hotel  pub  in  Liverpool,  the  force  said.  There  were  reportedly  more  than  100  people  gathered  z 
jb  at  around  midnight  on  Sunday,  playing  loud  music  and  disturbing  residents  nearby,  although  only  'a  number  of  people'  were  said  to  take 
The  Independent  adds,  "Seven  men  and  one  woman,  aged  between  21  and  33,  were  arrested  for  violent  disorder  and  drugs  offences.  Pubs 


aw  for  the  last  three  months  to  fight  the  spread  of  coronavirus,  with  Boris  Johnson  expected  to  allow  them  to  re-open  on  4  July,  albeit  with  ; 
ires  in  place  to  protect  customers." 

IOLOGY 


ks"  Hackers  Release  "Hundreds  Of  Thousands"  Of  Private  Records  On  Officers 

(6/22,  Taylor)  reports  hackers  have  "leaked  highly  sensitive  police  files  from  over  200  police  departments  across  the  country."  Activist 
a  "published  what  the  outlet  calls  'hundreds  of  gigabytes'  worth  of  potentially  sensitive  files'  from  police  departments  across  the  US."  The  gr 
information  dump  'BlueLeaks.'"  The  group  "compiled  the  records,  disseminating  them  into  a  searchable  database  that  can  pull  up  private  ir 
ce  badge  number."  Many  of  the  files  include  "information  such  as  memos,  emails,  and  officers'  personal  information".  The  group  "shared  in 
regarding  the  data  dump." 

VL  SECURITY 


Analysis:  Antifa  Rumors  Show  Ways  Information  Spreads  Locally 

ark  Times  (6/22,  Alba,  Decker)  examines  how  in  recent  weeks,  "residents  in  at  least  41  U.S.  cities  and  towns  became  alarmed  by  rum< 

ollective  of  anti-fascist  activists  known  as  antifa  was  headed  to  their  area,  according  to  an  analysis  by  The  New  York  Times.  In  many  cases,  th 
their  local  law  enforcement  for  help.  In  each  case,  it  was  for  a  threat  that  never  appeared."  On  the  local  level,  the  analysis  found  that  "the  sc 
formation  has  usually  been  more  subtle,  and  shows  the  complexity  of  stunting  misinformation  online.  The  bad  information  often  first  appea 
:acebook  post,  or  a  YouTube  video  there.  It  is  then  shared  on  online  spaces  like  local  Facebook  groups,  the  neighborhood  social  networking 
nd  community  texting  networks,"  which  "can  fall  under  the  radar  of  the  tech  companies  and  online  fact  checkers." 

Lives  Matter  Protests  Spread  To  White,  Rural  Areas.  The  Wall  Street  Journal  (6/22,  Carlton,  Subscription  Publication)  reports  tf 

r  racial  justice  have  quickly  spread  from  big  cities  to  small,  rural  towns  that  are  predominantly  white. 
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a  daily  news  briefing  selected  from  thousands  of  sources  by  the  editors  of  Bulletin  Media.  Neither  Bulletin  Media  nor  the  International  Association  of  Chiefs  of  Poli 
of  or  reliance  on  any  information  contained  in  this  briefing.  The  presence  of  articles  and/or  advertising  does  not  endorse,  nor  imply  endorsement  of,  any  products 


mentary  copy  of  The  Lead  was  sent  to  keith.morrison@cookcountyil.gov  as  a  member  benefit.  To  see  how  we  protect  our  data,  or  for  any  questions  on  data  access 
adia's  privacy  policy. 

ation  about  other  member  benefits,  please  contact  the  IACP  at  membership@theiacp.org  or  1.800.THE  IACP. 
al  Association  of  Chiefs  of  Police  |  44  Canal  Center  Plaza  Suite  200  |  Alexandria,  VA  22314 


3  2020  by  Bulletin  Media  |  11190  Sunrise  Valley  Drive  Suite  20  |  Reston,  VA  20191 


RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


To:  Douglas  Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov> 

Cc:  Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov>,  Adnan  Memon  (Sheriff) 

<Adnan. Memon@cookcountyil.gov> 

Sent:  June  23,  2020  7:02:37  AM  CDT 

Received:  June  23,  2020  7:06:00  AM  CDT 

This  is  a  different  article  from  the  International  Association  of  Chiefs  of  Police  that  relates  Netsentinal  is  a  Houston 
service  provider  for  Law  Enforcement. 

https://www.theblaze.com/news/blueleaks-hackers-release-countless-records-on-police-officers-all-searchable-by- 

badge-number 


From:  Keith  Morrison  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:45  AM 

To:  Douglas  Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


From:  Douglas  Maclean  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:26  AM 

To:  Keith  Morrison  (Sheriff)  <Keith.Morrison(5)cookcountviLgov>;  Amar  Patel  (Sheriff) 

<Amar. Patel@cookcountvil.gov>:  Adnan  Memon  (Sheriff)  <Adnan. Memon@cookcountvil.gov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Keith  - 


Doug 

From:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

Sent:  Tuesday,  June  23,  2020  6:20  AM 

To:  Douglas  Maclean  (Sheriff)  <Douglas. Maclean2@cookcountvil.gov>:  Amar  Patel  (Sheriff) 
<Amar. Patel@cookcountvil.gov>:  Adnan  Memon  (Sheriff)  <Adnan. Memon@cookcountvil.gov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Deputy  CIO  Maclean, 


Thanks, 

Morrison 


From:  Douglas  Maclean  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:10  AM 


To:  Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov>:  Keith  Morrison  (Sheriff) 
<Keith.Morrison@cookcountyil.gov>;  Adnan  Memon  (Sheriff)  <Adnan.Memon@cookcountyil.gov> 

Subject:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Krebs  on  Security  reports  Blue  Leaks  has  posted  24  years  of  LEA  and  fusion  center-related  data  as  the  result  of  a 
breach  on  Netsential,  an  internet  services  provider  to  LEAs  and  operational  fusion  centers.  The  data  includes  some 
information  related  to  sensitive  operations  and  a  significant  amount  of  Pll. 

The  Krebs  on  Security  story  can  be  found  here 

Keith  -  do  we  have  any  exposure  from  this  breach  either  directly  from  our  own  infrastructure  or  indirectly  as  the 
result  of  data-sharing  with  other  agencies?  Do  any  of  our  vendors  use  or  have  they  used  Netsential  for  any  of  their 
operations  from  1994  to  present? 


Douglas  MacLean 
Deputy  CIO 

Cook  County  Sheriffs  Office 
3026  S.  California 
South  Campus  Building  1 
Chicago  IL  60608 
312.877.2048  [c] 
773.674.8615  [d] 


RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


From: 

Cc: 


Sent: 

Received: 


Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov>,  Adnan  Memon  (Sheriff) 
<Adnan.Memon@cookcountyil.gov>,  Douglas  Maclean  (Sheriff) 
<Douglas.Maclean2@cookcountyil.gov> 

June  23,  2020  7:10:54  AM  CDT 
June  23,  2020  7:10:56  AM  CDT 


Attachments:  report-workforce-software-2020-06-1 9.xlsx,  report-workforce-software-2020- 

06-1 9.pdf 


This  is  a  different  article  from  the  International  Association  of  Chiefs  of  Police  that  relates  Netsentinal  is  a  Houston 
service  provider  for  Law  Enforcement. 


https://www.theblaze.com/news/blueleaks-hackers-release-countless-records-on-police-officers-all-searchable-by- 

badge-number 


I  think  our  only  risk  from  doxing  would  be  workforce.  I  pulled  the  attached  reports  last  Friday  and  provided  them  to 
Chuck  at  Homeland  for  review. 


From:  Keith  Morrison  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:45  AM 

To:  Douglas  Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


From:  Douglas  Maclean  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:26  AM 

To:  Keith  Morrison  (Sheriff)  <Keith.Morrison(5)cookcountviLgov>;  Amar  Patel  (Sheriff) 
<Amar.Patel(5)cookcountviLgov>;  Adnan  Memon  (Sheriff)  <Adnan.Memon(5)cookcountviLgov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Keith  - 


Doug 

From:  Keith  Morrison  (Sheriff)  <Keith.  Morrison@cookcountvil.gov> 

Sent:  Tuesday,  June  23,  2020  6:20  AM 

To:  Douglas  Maclean  (Sheriff)  <Douglas. Maclean2@cookcountvil.gov>:  Amar  Patel  (Sheriff) 
<Amar. Patel@cookcountvil.gov>:  Adnan  Memon  (Sheriff)  <Adnan. Memon@cookcountvil.gov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Deputy  CIO  Maclean, 


Thanks, 


Morrison 


From:  Douglas  Maclean  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:10  AM 

To:  Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov>:  Keith  Morrison  (Sheriff) 
<Keith.Morrison@cookcountyil.gov>;  Adnan  Memon  (Sheriff)  <Adnan.Memon@cookcountyil.gov> 

Subject:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Krebs  on  Security  reports  Blue  Leaks  has  posted  24  years  of  LEA  and  fusion  center-related  data  as  the  result  of  a 
breach  on  Netsential,  an  internet  services  provider  to  LEAs  and  operational  fusion  centers.  The  data  includes  some 
information  related  to  sensitive  operations  and  a  significant  amount  of  Pll. 

The  Krebs  on  Security  story  can  be  found  here 

Keith  -  do  we  have  any  exposure  from  this  breach  either  directly  from  our  own  infrastructure  or  indirectly  as  the 
result  of  data-sharing  with  other  agencies?  Do  any  of  our  vendors  use  or  have  they  used  Netsential  for  any  of  their 
operations  from  1994  to  present? 


Douglas  MacLean 
Deputy  CIO 

Cook  County  Sheriffs  Office 
3026  S.  California 
South  Campus  Building  1 
Chicago  IL  60608 
312.877.2048  [c] 
773.674.8615  [d] 


RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


From:  Keith  Morrison  (Sheriff)  </0= EXC H AN G E LABS/O U = EXC H AN G E  ADMINISTRATIVE 

GROUP 

(FYDIBOHF23SPDLT)/CN=RECIPIENTS/CN=D2EBEC5431A14B10A53942341  DBD54F 
4-KEITH  MORRI> 

Cc:  Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov>,  Adnan  Memon  (Sheriff) 

<Adnan.Memon@cookcountyil.gov>,  Douglas  Maclean  (Sheriff) 
<Douglas.Maclean2@cookcountyil.gov> 

Sent:  June  23,  2020  7:10:54  AM  CDT 

Received:  June  23,  2020  7:10:00  AM  CDT 

Attachments:  report-workforce-software-2020-06- 1 9.pdf,  report-workforce-software-2020-06- 1 9.xlsx 

This  is  a  different  article  from  the  International  Association  of  Chiefs  of  Police  that  relates  Netsentinal  is  a  Houston 
service  provider  for  Law  Enforcement. 

https://www.theblaze.com/news/blueleaks-hackers-release-countless-records-on-police-officers-all-searchable-by- 

badge-number 

I  think  our  only  risk  from  doxing  would  be  workforce.  I  pulled  the  attached  reports  last  Friday  and  provided  them  to 
Chuck  at  Homeland  for  review. 

From:  Keith  Morrison  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:45  AM 

To:  Douglas  Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov> 

Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


From:  Douglas  Maclean  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:26  AM 

To:  Keith  Morrison  (Sheriff)  <Keith. Morrison@cookcountvil.gov>:  Amar  Patel  (Sheriff) 
<Amar.Patel@cookcountyil.gov>:  Adnan  Memon  (Sheriff)  <Adnan. Memon@cookcountvil.gov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Keith  - 


Doug 

From:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

Sent:  Tuesday,  June  23,  2020  6:20  AM 

To:  Douglas  Maclean  (Sheriff)  <Douglas. Maclean2@cookcountvil.gov>:  Amar  Patel  (Sheriff) 
<Amar.Patel@cookcountyil.gov>:  Adnan  Memon  (Sheriff)  <Adnan. Memon@cookcountvil.gov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Deputy  CIO  Maclean, 


Thanks, 


Morrison 


From:  Douglas  Maclean  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:10  AM 

To:  Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov>:  Keith  Morrison  (Sheriff) 
<Keith.Morrison@cookcountyil.gov>;  Adnan  Memon  (Sheriff)  <Adnan.Memon@cookcountyil.gov> 

Subject:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Krebs  on  Security  reports  Blue  Leaks  has  posted  24  years  of  LEA  and  fusion  center-related  data  as  the  result  of  a 
breach  on  Netsential,  an  internet  services  provider  to  LEAs  and  operational  fusion  centers.  The  data  includes  some 
information  related  to  sensitive  operations  and  a  significant  amount  of  Pll. 

The  Krebs  on  Security  story  can  be  found  here 

Keith  -  do  we  have  any  exposure  from  this  breach  either  directly  from  our  own  infrastructure  or  indirectly  as  the 
result  of  data-sharing  with  other  agencies?  Do  any  of  our  vendors  use  or  have  they  used  Netsential  for  any  of  their 
operations  from  1994  to  present? 


Douglas  MacLean 
Deputy  CIO 

Cook  County  Sheriffs  Office 
3026  S.  California 
South  Campus  Building  1 
Chicago  IL  60608 
312.877.2048  [c] 
773.674.8615  [d] 


IT  Security  News  Blast  -  6-23-2020 

From:  Mike  Hamilton  <Michael.Hamilton@CI.Security> 

To:  Keith.Morrison@cookcountyil.gov,  Keith  Morrison  (Sheriff) 

<Keith.Morrison@cookcountyil.gov> 

Sent:  June  23,  2020  7:14:12  AM  CDT 

Received:  June  23,  2020  7:14:21  AM  CDT 


External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 


Tomorrow,  6/24  -  [WEBINAR]  Mid-Pandemic  Attacks  and  How  to  Thwart  Them 
with  MDR 

There’s  still  time  to  register  for  tomorrow’s  webinar  at  the  MIDMRKT  June  virtual 
showcase!  When  organizations  changed  their  work  habits  in  unprecedented  ways 
this  year,  they  opened  the  door  to  significant  cyber  risks.  Unfortunately,  we  are 
seeing  those  risks  turn  into  exploited  vulnerabilities  now.  In  this  webinar  on 
Wednesday,  June  24,  InfoSec  Veteran  Mike  Hamilton  will  show  you  what  criminals 
are  doing,  how  Managed  Detection  and  Response  can  stop  it,  and  what  to  do  if  you 
become  the  victim  of  a  ransomware  gang.  It’s  free  to  register  for  tomorrow’s  hour- 
long  event,  starting  at  Noon  ET/9am  PT.  Bring  your  questions  for  Q&A  at  the  end. 

https://virtual.midmrkt.eom/s/virtual-technoloqy-showcase-iune2020 


‘BlueLeaks’  Exposes  Files  from  Hundreds  of  Police  Departments 

“Preliminary  analysis  of  the  data  contained  in  this  leak  suggests  that  Netsential,  a 
web  services  company  used  by  multiple  fusion  centers,  law  enforcement,  and  other 


government  agencies  across  the  United  States,  was  the  source  of  the  compromise,” 
the  NFCA  wrote.  “Netsential  confirmed  that  this  compromise  was  likely  the  result  of  a 
threat  actor  who  leveraged  a  compromised  Netsential  customer  user  account  and 
the  web  platform’s  upload  feature  to  introduce  malicious  content,  allowing  for  the 
exfiltration  of  other  Netsential  customer  data.” 

https://krebsonsecuritv.com/2020/06/blueleaks-exposes-files-from-hundreds-of- 

police-departments/ 


Oracle’s  BlueKai  tracks  you  across  the  web.  That  data  spilled  online 
Billions  of  records  exposed. 

Tech  giant  Oracle  is  one  of  a  few  companies  in  Silicon  Valley  that  has  near- 
perfected  the  art  of  tracking  people  across  the  internet.  The  company  has  spent  a 
decade  and  billions  of  dollars  buying  startups  to  build  its  very  own  panopticon  of 
users’  web  browsing  data.  [...]  TechCrunch  reviewed  the  data  shared  by  Sen  and 
found  names,  home  addresses,  email  addresses  and  other  identifiable  data  in  the 
database.  The  data  also  revealed  sensitive  users’  web  browsing  activity  —  from 
purchases  to  newsletter  unsubscribes. 

https://techcrunch.eom/2020/06/1 9/oracle-bluekai-web-trackinq/?quccounter=1 


Ransomware  group  auctions  Crozer-Keystone  Health  System  data  on  darknet 

Netwalker,  a  ransomware  operator  that  threatens  to  publish  data  online  if  ransoms 
aren't  paid,  hacked  Springfield,  Pa. -based  Crozer-Keystone  Health  System  and  is 
auctioning  off  its  data  online,  according  to  Cointelegraph.  [...]  Cointelegraph  was  able 
to  access  Netwalker's  alleged  publication  on  June  19,  which  showed  "dozens  of 
folders  with  an  undisclosed  amount  of  data,  mostly  concerning  finances,  but  nothing 
related  to  medical  records  of  patients,"  according  to  the  report.  Netwalker  claimed 
Crozer-Keystone  declined  to  pay  for  the  ransom  the  group  demanded  in  Bitcoin. 

https://www.beckershospitalreview.com/cvbersecurity/ransomware-group-auctions- 

crozer-kevstone-health-svstem-data-on-darknet.html 


Key  cause  of  cyber  loss  identified  in  new  report 


“There  is  always  going  to  be  a  human  element,  and  it  is  impossible  to  get  to  100% 
compliance  with  various  rules,  regulations  and  best  practices,”  said  Mike  Palotay, 
chief  underwriting  officer  at  Tokio  Marine  HCC.  He  pointed  to  the  healthcare  industry, 
which  has  a  serious  employee  negligence  risk  because  there  are  many  people  with 
access  to  private  information  that  is  being  sent  to  different  recipients. 

https://www.insurancebusinessmag.com/us/news/cvber/kev-cause-of-cvber-loss- 

identified-in-new-report-225838.aspx 


Cybersecurity  skills  shortage  amid  attacks 

"Traditionally  we've  done  a  lot  of  importing  skills  and  that's  been  really  fantastic  to 
bring  in  experts  in  some  of  these  areas.  But  that's  not  an  option  anymore  -  we  have 
to  grow  these  skills."  Not-for-profit  AustCyber's  research  predicts  a  shortage  of 
18,000  cyber  experts  by  2026.  With  unemployment  on  the  rise  during  the  pandemic, 
Ms  Souness  believes  there's  an  opportunity  to  create  jobs.  "We've  got  hundreds  of 
thousands  of  roles  going,  we've  got  new  records  in  unemployment,  if  only  we  were 
upskilling  people,"  Ms  Souness  said. 

https://au.news.vahoo.com/cvbersecuritv-skills-shortage-amid-attacks-003800589- 

spt.html 


Why  SMEs  are  increasing  their  cyber  insurance  budgets 

Research  has  also  suggested  cybercriminals  view  SMEs  as  possible  entry  points  to 
gain  access  to  the  network  of  a  larger  company.  Often,  the  damage  and  recovery 
costs  of  businesses  having  to  deal  with  the  aftermath  of  malicious  attacks  leads  to 
not  only  plummet  productivity,  but  in  some  cases,  to  deteriorating  trust  between  firm 
and  clients. 

https://techhg.com/2020/06/why-smes-are-increasing-budgets-for-cvber-insurance/ 


Companies  are  rethinking  their  approach  to  privacy  management 

Twenty-two  percent  of  respondents  said  personal  device  security  during  the 
pandemic  has  added  a  great  deal  of  risk  to  their  businesses.  “Personal  device 
security”  received  the  highest  proportion  of  “a  great  deal  of  risk”  responses, 


compared  to  the  other  four  response  options. 

A  majority  of  respondents  said  that  third-party  data,  supply  chain,  personal-device 
security,  unintentional  data  sharing,  and  required  or  voluntary  data  sharing  for  public 
health  purposes  all  added  at  least  a  moderate  amount  of  risk  to  their  businesses. 

https://www.helpnetsecuritv.com/2020/06/22/privacy-management/ 


Addressing  Cybersecurity  in  The  Time  Of  COVID-19  and  Beyond 

An  enterprise-wide  strategic  risk.  Although  there  is  an  IT  component, 
cybersecurity  is  not  just  an  IT  problem.  It  is  also  a  human  resource  issue  and  a 
financial  issue,  so  it  should  be  woven  into  the  business. 

Legal  and  disclosure  implications.  Boards  need  to  be  aware  of  their  unique 
legal  obligations,  which  vary  from  country  to  country  and  by  sector. 

Board  oversight  structure  and  access  to  expertise.  To  create  an  effective 
cybersecurity  strategy,  boards  need  to  bring  in  outside  cyber  and  privacy  experts. 

An  enterprise  framework  for  managing  cyber  risk.  Boards  and  management 
across  the  enterprise  must  work  together  in  developing  a  cyber  strategy,  as  well  as 
understand  each  other’s  roles. 

[...] 

https://www.financialexecutives.org/FEI-Daily/June-2020/Addressing-Cvbersecuritv- 

in-The-Time-Of-COVID-1 9-a.aspx 


Government  groups  work  together  to  mitigate  cybersecurity  risks  in  solar 
development 

The  rapid  growth  and  importance  of  solar  energy  has  elevated  the  critical  need 
among  state-level  decision  makers  to  evaluate  the  potential  cybersecurity 
implications  of  solar  deployment  and  work  with  federal  and  private-sector 
stakeholders  to  mitigate  those  risks.  Newer  two-way  communication  technologies 
and  remote  grid  support  are  revolutionizing  how  the  grid  operates,  but  also  result  in  a 
system  more  exposed  to  cyber  vulnerabilities.  NASEO  and  NARUC  seek  to 
proactively  address  cyber  threats  in  all  energy  areas,  including  solar  infrastructure. 


https://www.solarpowerworldonline.com/2020/06/government-groups-partner-to- 

mitigate-cvbersecurity-risks-in-solar-development/ 


Power  transformers  and  Aurora 

In  general  if  we  want  to  attack  substation  functions,  there  are  a  few  options  in 
diagram  1.  The  attack  can  come  over  the  network,  the  SCADA  is  frequently 
connected  to  the  corporate  network  or  even  to  the  Internet.  Famous  example  is  the 
Ukraine  attack  on  the  power  distribution.  We  can  try  penetrating  the  WAN,  these  are 
not  always  private  connections  so  there  are  opportunities  here.  So  far  never  seen  an 
example  of  this.  And  we  can  attack  the  time  source,  time  is  a  very  important  element 
in  the  control  of  a  power  system. 

https://otcvbersecuritv.blog/2020/06/20/power-transformers-and-aurora/ 


During  global  pandemic,  USCYBERCOM  trains  virtually  to  defend  networks, 
protect  nation 

Over  the  period  of  two  weeks,  Cyber  Flag  20-2  will  host  more  than  500  personnel 
worldwide,  spanning  across  nine  different  time  zones  and  17  cyber  teams. 
Participants  include  three  allied  nations,  the  Air  National  Guard,  the  Coast  Guard, 
the  U.S.  Army  Corps  of  Engineers,  U.S.  Postal  Service,  U.S.  Dept,  of  Energy  and 
multiple  service  cyber  components  across  the  DOD. 

https://www.cybercom.mil/Media/News/Article/2227651/during-global-pandemic- 

uscvbercom-trains-virtuallv-to-defend-networks-protect-n/ 


Key  Solarium  recommendations  find  a  home  in  the  defense  bill 

The  Subcommittee  on  Intelligence  and  Emerging  Threats  adopted  a  markup  June  22 
that  includes  provisions  directing  the  Department  of  Defense  to  assess  the  national 
security  risks  posed  by  quantum  computing,  assess  the  impact  of  greater  private- 
public  collaboration  between  government  and  critical  infrastructure  owners  and 
operators,  clarify  the  cybersecurity  capabilities  and  interoperability  of  the  National 
Guard  and  expanding  a  program  authorizing  DOD  employees  to  use  paid  leave  for 
cybersecurity  education. 


https://fcw.com/articles/2020/06/22/iohnson-solarium-ndaa-markup-emerging.aspx 


Estonia’s  Crucial  Role  in  Tackling  Growing  Cyber  Threats 

The  lesson  from  Estonia  for  any  country  wishing  to  undergo  digital  transformation  is 
simple  -  that  threats  to  peace  and  security  in  the  physical  world  can  be  translated  to 
cyberspace.  Through  developing  its  cyber  incident  response,  the  government’s  own 
cyber  security  capacity  and  its  digital  infrastructure,  Estonia  became  a  model  and  a 
leader  on  digitization  and  e-governance  efforts.  And  although  those  involved  in 
developing  the  governance  of  cyberspace  pay  credence  to  a  multi-stakeholder 
approach  -  involving  actors  from  the  private  sector,  technical  community,  civil  society 
and  academia  -  states  remain  the  key  players. 

https://www.chathamhouse.org/expert/comment/estonia-s-crucial-role-tackling- 

growing-cyber-threats# 


Does  a  generalization  of  tracking  data  cover  up  our  traces  on  the  internet? 

Many  providers  of  tracking  services  advertise  secure  data  protection  by  generalizing 
datasets  and  anonymizing  data  in  this  way.  [...]  Strufe,  together  with  his  team  and 
colleagues  of  TUD,  have  now  studied  whether  this  method  really  allows  no 
conclusions  to  be  drawn  with  respect  to  the  individual.  With  the  help  of  a  large 
volume  of  metadata  of  German  websites  with  66  million  users  and  over  2  billion  page 
views,  the  computer  scientists  succeeded  in  not  only  drawing  conclusions  with 
respect  to  the  websites  accessed,  but  also  with  respect  to  the  chains  of  page  views, 
the  so-called  click  traces. 

https://www.helpnetsecuritv.com/2020/06/22/generalization-of-tracking-data/ 


Privacy  experts  say  many  coronavirus  apps  aren't  doing  enough  to  safeguard 
users'  information  [Subscription] 

Developers  of  the  apps,  researchers  say,  did  not  implement  strong  digital  protections 
that  are  standard  on  other  technology  that  deals  with  sensitive  personal  or  health 
information  And  many  are  siphoning  data  to  third  parties  —  which  means  peoples' 
private  information  could  be  used  for  targeted  advertising  or  to  track  them  across 


other,  non-related  apps. 

https://www.washingtonpost.com/news/powerpost/paloma/the-cvbersecurity- 

202/2020/06/22/the-cvbersecuritv-202-privacv-experts-sav-many-coronavirus-apps- 

aren-t-doinq-enouqh-to-safeguard-users-information/5eefae20602ff12947e91075/ 


Crooks  abuse  Google  Analytics  to  conceal  theft  of  payment  card  data 

One  challenge  in  pulling  off  the  hack  is  bypassing  website  security  policies  or 
concealing  the  exfiltration  of  massive  amounts  of  sensitive  data  from  endpoint 
security  applications  installed  on  the  infected  network.  Researchers  from  Kaspersky 
Lab  on  Monday  said  that  they  have  recently  observed  about  two  dozen  infected  sites 
that  found  a  novel  way  to  achieve  this.  Instead  of  sending  it  to  attacker-controlled 
servers,  the  attackers  send  it  to  Google  Analytics  accounts  they  control.  Since  the 
Google  service  is  so  widely  used,  ecommerce  site  security  policies  generally  fully 
trust  it  to  receive  data. 

https://arstechnica.com/information-technoloqv/2020/06/qooqle-analvtics-trick- 

allows-crooks-to-hide-card-skimming/ 


AMD:  Fixes  For  High-Severity  SMM  Callout  Flaws  Upcoming 

“AMD  is  aware  of  new  research  related  to  a  potential  vulnerability  in  AMD  software 
technology  supplied  to  motherboard  manufacturers  for  use  in  their  Unified  Extensible 
Firmware  Interface  (UEFI)  infrastructure  and  plans  to  complete  delivery  of  updated 
versions  designed  to  mitigate  the  issue  by  the  end  of  June  2020,”  according  to  AMD. 

https://threatpost.com/amd-fixes-for-hiqh-severitv-smm-callout-flaws- 

upcoming/1 56787/ 


Elon  Musk  invites  users  to  test  Starlink  space  internet 

The  $36  billion  company  now  has  over  500  satellites  in  orbit.  Last  week  it  announced 
that  trials  of  its  space-based  Internet  platform  could  start  within  weeks.  An  invitation 
to  sign  up  for  Starlink  updates  was  published  on  the  startup’s  website.  Users  sign  up 
with  an  email  address  and  zip  code,  and  are  told  Starlink  will  begin  beta-testing  this 
summer  in  the  Northern  hemisphere.  The  company  promises  to  notify  everyone  with 


the  right  zip  code  if  trials  are  going  on  in  their  area. 

https://decrvpt.co/33080/elon-musk-invites-users-to-test-starlink-space-internet 
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Tomorrow,  6/24  -  [WEBINAR]  Mid-Pandemic  Attacks  and  How  to  Thwart  Them 
with  MDR 

There’s  still  time  to  register  for  tomorrow’s  webinar  at  the  MIDMRKT  June  virtual 
showcase!  When  organizations  changed  their  work  habits  in  unprecedented  ways 
this  year,  they  opened  the  door  to  significant  cyber  risks.  Unfortunately,  we  are 
seeing  those  risks  turn  into  exploited  vulnerabilities  now.  In  this  webinar  on 
Wednesday,  June  24,  InfoSec  Veteran  Mike  Hamilton  will  show  you  what  criminals 
are  doing,  how  Managed  Detection  and  Response  can  stop  it,  and  what  to  do  if  you 
become  the  victim  of  a  ransomware  gang.  It’s  free  to  register  for  tomorrow’s  hour- 
long  event,  starting  at  Noon  ET/9am  PT.  Bring  your  questions  for  Q&A  at  the  end. 

https://virtual.midmrkt.eom/s/virtual-technoloqy-showcase-iune2020 


‘BlueLeaks’  Exposes  Files  from  Hundreds  of  Police  Departments 

“Preliminary  analysis  of  the  data  contained  in  this  leak  suggests  that  Netsential,  a 
web  services  company  used  by  multiple  fusion  centers,  law  enforcement,  and  other 


government  agencies  across  the  United  States,  was  the  source  of  the  compromise,” 
the  NFCA  wrote.  “Netsential  confirmed  that  this  compromise  was  likely  the  result  of  a 
threat  actor  who  leveraged  a  compromised  Netsential  customer  user  account  and 
the  web  platform’s  upload  feature  to  introduce  malicious  content,  allowing  for  the 
exfiltration  of  other  Netsential  customer  data.” 

https://krebsonsecuritv.com/2020/06/blueleaks-exposes-files-from-hundreds-of- 

police-departments/ 


Oracle’s  BlueKai  tracks  you  across  the  web.  That  data  spilled  online 
Billions  of  records  exposed. 

Tech  giant  Oracle  is  one  of  a  few  companies  in  Silicon  Valley  that  has  near- 
perfected  the  art  of  tracking  people  across  the  internet.  The  company  has  spent  a 
decade  and  billions  of  dollars  buying  startups  to  build  its  very  own  panopticon  of 
users’  web  browsing  data.  [...]  TechCrunch  reviewed  the  data  shared  by  Sen  and 
found  names,  home  addresses,  email  addresses  and  other  identifiable  data  in  the 
database.  The  data  also  revealed  sensitive  users’  web  browsing  activity  —  from 
purchases  to  newsletter  unsubscribes. 

https://techcrunch.eom/2020/06/1 9/oracle-bluekai-web-trackinq/?quccounter=1 


Ransomware  group  auctions  Crozer-Keystone  Health  System  data  on  darknet 

Netwalker,  a  ransomware  operator  that  threatens  to  publish  data  online  if  ransoms 
aren't  paid,  hacked  Springfield,  Pa. -based  Crozer-Keystone  Health  System  and  is 
auctioning  off  its  data  online,  according  to  Cointelegraph.  [...]  Cointelegraph  was  able 
to  access  Netwalker's  alleged  publication  on  June  19,  which  showed  "dozens  of 
folders  with  an  undisclosed  amount  of  data,  mostly  concerning  finances,  but  nothing 
related  to  medical  records  of  patients,"  according  to  the  report.  Netwalker  claimed 
Crozer-Keystone  declined  to  pay  for  the  ransom  the  group  demanded  in  Bitcoin. 

https://www.beckershospitalreview.com/cvbersecurity/ransomware-group-auctions- 

crozer-kevstone-health-svstem-data-on-darknet.html 


Key  cause  of  cyber  loss  identified  in  new  report 


“There  is  always  going  to  be  a  human  element,  and  it  is  impossible  to  get  to  100% 
compliance  with  various  rules,  regulations  and  best  practices,”  said  Mike  Palotay, 
chief  underwriting  officer  at  Tokio  Marine  HCC.  He  pointed  to  the  healthcare  industry, 
which  has  a  serious  employee  negligence  risk  because  there  are  many  people  with 
access  to  private  information  that  is  being  sent  to  different  recipients. 

https://www.insurancebusinessmag.com/us/news/cvber/kev-cause-of-cvber-loss- 

identified-in-new-report-225838.aspx 


Cybersecurity  skills  shortage  amid  attacks 

"Traditionally  we've  done  a  lot  of  importing  skills  and  that's  been  really  fantastic  to 
bring  in  experts  in  some  of  these  areas.  But  that's  not  an  option  anymore  -  we  have 
to  grow  these  skills."  Not-for-profit  AustCyber's  research  predicts  a  shortage  of 
18,000  cyber  experts  by  2026.  With  unemployment  on  the  rise  during  the  pandemic, 
Ms  Souness  believes  there's  an  opportunity  to  create  jobs.  "We've  got  hundreds  of 
thousands  of  roles  going,  we've  got  new  records  in  unemployment,  if  only  we  were 
upskilling  people,"  Ms  Souness  said. 

https://au.news.vahoo.com/cvbersecuritv-skills-shortage-amid-attacks-003800589- 

spt.html 


Why  SMEs  are  increasing  their  cyber  insurance  budgets 

Research  has  also  suggested  cybercriminals  view  SMEs  as  possible  entry  points  to 
gain  access  to  the  network  of  a  larger  company.  Often,  the  damage  and  recovery 
costs  of  businesses  having  to  deal  with  the  aftermath  of  malicious  attacks  leads  to 
not  only  plummet  productivity,  but  in  some  cases,  to  deteriorating  trust  between  firm 
and  clients. 

https://techhg.com/2020/06/why-smes-are-increasing-budgets-for-cvber-insurance/ 


Companies  are  rethinking  their  approach  to  privacy  management 

Twenty-two  percent  of  respondents  said  personal  device  security  during  the 
pandemic  has  added  a  great  deal  of  risk  to  their  businesses.  “Personal  device 
security”  received  the  highest  proportion  of  “a  great  deal  of  risk”  responses, 


compared  to  the  other  four  response  options. 

A  majority  of  respondents  said  that  third-party  data,  supply  chain,  personal-device 
security,  unintentional  data  sharing,  and  required  or  voluntary  data  sharing  for  public 
health  purposes  all  added  at  least  a  moderate  amount  of  risk  to  their  businesses. 

https://www.helpnetsecuritv.com/2020/06/22/privacy-management/ 


Addressing  Cybersecurity  in  The  Time  Of  COVID-19  and  Beyond 

An  enterprise-wide  strategic  risk.  Although  there  is  an  IT  component, 
cybersecurity  is  not  just  an  IT  problem.  It  is  also  a  human  resource  issue  and  a 
financial  issue,  so  it  should  be  woven  into  the  business. 

Legal  and  disclosure  implications.  Boards  need  to  be  aware  of  their  unique 
legal  obligations,  which  vary  from  country  to  country  and  by  sector. 

Board  oversight  structure  and  access  to  expertise.  To  create  an  effective 
cybersecurity  strategy,  boards  need  to  bring  in  outside  cyber  and  privacy  experts. 

An  enterprise  framework  for  managing  cyber  risk.  Boards  and  management 
across  the  enterprise  must  work  together  in  developing  a  cyber  strategy,  as  well  as 
understand  each  other’s  roles. 

[...] 

https://www.financialexecutives.org/FEI-Daily/June-2020/Addressing-Cvbersecuritv- 

in-The-Time-Of-COVID-1 9-a.aspx 


Government  groups  work  together  to  mitigate  cybersecurity  risks  in  solar 
development 

The  rapid  growth  and  importance  of  solar  energy  has  elevated  the  critical  need 
among  state-level  decision  makers  to  evaluate  the  potential  cybersecurity 
implications  of  solar  deployment  and  work  with  federal  and  private-sector 
stakeholders  to  mitigate  those  risks.  Newer  two-way  communication  technologies 
and  remote  grid  support  are  revolutionizing  how  the  grid  operates,  but  also  result  in  a 
system  more  exposed  to  cyber  vulnerabilities.  NASEO  and  NARUC  seek  to 
proactively  address  cyber  threats  in  all  energy  areas,  including  solar  infrastructure. 


https://www.solarpowerworldonline.com/2020/06/government-groups-partner-to- 

mitigate-cvbersecurity-risks-in-solar-development/ 


Power  transformers  and  Aurora 

In  general  if  we  want  to  attack  substation  functions,  there  are  a  few  options  in 
diagram  1.  The  attack  can  come  over  the  network,  the  SCADA  is  frequently 
connected  to  the  corporate  network  or  even  to  the  Internet.  Famous  example  is  the 
Ukraine  attack  on  the  power  distribution.  We  can  try  penetrating  the  WAN,  these  are 
not  always  private  connections  so  there  are  opportunities  here.  So  far  never  seen  an 
example  of  this.  And  we  can  attack  the  time  source,  time  is  a  very  important  element 
in  the  control  of  a  power  system. 

https://otcvbersecuritv.blog/2020/06/20/power-transformers-and-aurora/ 


During  global  pandemic,  USCYBERCOM  trains  virtually  to  defend  networks, 
protect  nation 

Over  the  period  of  two  weeks,  Cyber  Flag  20-2  will  host  more  than  500  personnel 
worldwide,  spanning  across  nine  different  time  zones  and  17  cyber  teams. 
Participants  include  three  allied  nations,  the  Air  National  Guard,  the  Coast  Guard, 
the  U.S.  Army  Corps  of  Engineers,  U.S.  Postal  Service,  U.S.  Dept,  of  Energy  and 
multiple  service  cyber  components  across  the  DOD. 

https://www.cybercom.mil/Media/News/Article/2227651/during-global-pandemic- 

uscvbercom-trains-virtuallv-to-defend-networks-protect-n/ 


Key  Solarium  recommendations  find  a  home  in  the  defense  bill 

The  Subcommittee  on  Intelligence  and  Emerging  Threats  adopted  a  markup  June  22 
that  includes  provisions  directing  the  Department  of  Defense  to  assess  the  national 
security  risks  posed  by  quantum  computing,  assess  the  impact  of  greater  private- 
public  collaboration  between  government  and  critical  infrastructure  owners  and 
operators,  clarify  the  cybersecurity  capabilities  and  interoperability  of  the  National 
Guard  and  expanding  a  program  authorizing  DOD  employees  to  use  paid  leave  for 
cybersecurity  education. 


https://fcw.com/articles/2020/06/22/iohnson-solarium-ndaa-markup-emerging.aspx 


Estonia’s  Crucial  Role  in  Tackling  Growing  Cyber  Threats 

The  lesson  from  Estonia  for  any  country  wishing  to  undergo  digital  transformation  is 
simple  -  that  threats  to  peace  and  security  in  the  physical  world  can  be  translated  to 
cyberspace.  Through  developing  its  cyber  incident  response,  the  government’s  own 
cyber  security  capacity  and  its  digital  infrastructure,  Estonia  became  a  model  and  a 
leader  on  digitization  and  e-governance  efforts.  And  although  those  involved  in 
developing  the  governance  of  cyberspace  pay  credence  to  a  multi-stakeholder 
approach  -  involving  actors  from  the  private  sector,  technical  community,  civil  society 
and  academia  -  states  remain  the  key  players. 

https://www.chathamhouse.org/expert/comment/estonia-s-crucial-role-tackling- 

growing-cyber-threats# 


Does  a  generalization  of  tracking  data  cover  up  our  traces  on  the  internet? 

Many  providers  of  tracking  services  advertise  secure  data  protection  by  generalizing 
datasets  and  anonymizing  data  in  this  way.  [...]  Strufe,  together  with  his  team  and 
colleagues  of  TUD,  have  now  studied  whether  this  method  really  allows  no 
conclusions  to  be  drawn  with  respect  to  the  individual.  With  the  help  of  a  large 
volume  of  metadata  of  German  websites  with  66  million  users  and  over  2  billion  page 
views,  the  computer  scientists  succeeded  in  not  only  drawing  conclusions  with 
respect  to  the  websites  accessed,  but  also  with  respect  to  the  chains  of  page  views, 
the  so-called  click  traces. 

https://www.helpnetsecuritv.com/2020/06/22/generalization-of-tracking-data/ 


Privacy  experts  say  many  coronavirus  apps  aren't  doing  enough  to  safeguard 
users'  information  [Subscription] 

Developers  of  the  apps,  researchers  say,  did  not  implement  strong  digital  protections 
that  are  standard  on  other  technology  that  deals  with  sensitive  personal  or  health 
information  And  many  are  siphoning  data  to  third  parties  —  which  means  peoples' 
private  information  could  be  used  for  targeted  advertising  or  to  track  them  across 


other,  non-related  apps. 

https://www.washingtonpost.com/news/powerpost/paloma/the-cvbersecurity- 

202/2020/06/22/the-cvbersecuritv-202-privacv-experts-sav-many-coronavirus-apps- 

aren-t-doinq-enouqh-to-safeguard-users-information/5eefae20602ff12947e91075/ 


Crooks  abuse  Google  Analytics  to  conceal  theft  of  payment  card  data 

One  challenge  in  pulling  off  the  hack  is  bypassing  website  security  policies  or 
concealing  the  exfiltration  of  massive  amounts  of  sensitive  data  from  endpoint 
security  applications  installed  on  the  infected  network.  Researchers  from  Kaspersky 
Lab  on  Monday  said  that  they  have  recently  observed  about  two  dozen  infected  sites 
that  found  a  novel  way  to  achieve  this.  Instead  of  sending  it  to  attacker-controlled 
servers,  the  attackers  send  it  to  Google  Analytics  accounts  they  control.  Since  the 
Google  service  is  so  widely  used,  ecommerce  site  security  policies  generally  fully 
trust  it  to  receive  data. 

https://arstechnica.com/information-technoloqv/2020/06/qooqle-analvtics-trick- 

allows-crooks-to-hide-card-skimming/ 


AMD:  Fixes  For  High-Severity  SMM  Callout  Flaws  Upcoming 

“AMD  is  aware  of  new  research  related  to  a  potential  vulnerability  in  AMD  software 
technology  supplied  to  motherboard  manufacturers  for  use  in  their  Unified  Extensible 
Firmware  Interface  (UEFI)  infrastructure  and  plans  to  complete  delivery  of  updated 
versions  designed  to  mitigate  the  issue  by  the  end  of  June  2020,”  according  to  AMD. 

https://threatpost.com/amd-fixes-for-hiqh-severitv-smm-callout-flaws- 

upcoming/1 56787/ 


Elon  Musk  invites  users  to  test  Starlink  space  internet 

The  $36  billion  company  now  has  over  500  satellites  in  orbit.  Last  week  it  announced 
that  trials  of  its  space-based  Internet  platform  could  start  within  weeks.  An  invitation 
to  sign  up  for  Starlink  updates  was  published  on  the  startup’s  website.  Users  sign  up 
with  an  email  address  and  zip  code,  and  are  told  Starlink  will  begin  beta-testing  this 
summer  in  the  Northern  hemisphere.  The  company  promises  to  notify  everyone  with 


the  right  zip  code  if  trials  are  going  on  in  their  area. 

https://decrvpt.co/33080/elon-musk-invites-users-to-test-starlink-space-internet 
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RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


From:  Douglas  Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov> 

To:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

Sent:  June  23,  2020  7:17:01  AM  CDT 

Received:  June  23,  2020  7:17:03  AM  CDT 

Thanks. 


Douglas  MacLean 
Deputy  CIO,  BOIT 
Cook  County  Sheriffs  Office 
South  Campus,  Building  1 
3rd  Floor 
Chicago,  IL  60608 

773.674.8615  [d] 
312.877.2048  [c] 

From  Mobile 


- Original  message - 

From:  "Keith  Morrison  (Sheriff)"  <Keith.Morrison@cookcountyil.gov> 

Date:  6/23/20  06:45  (GMT-06:00) 

To:  "Douglas  Maclean  (Sheriff)"  <Douglas.Maclean2@cookcountyil.gov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


From:  Douglas  Maclean  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:26  AM 

To:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov>;  Amar  Patel  (Sheriff) 
<Amar.Patel@cookcountyil.gov>;  Adnan  Memon  (Sheriff)  <Adnan. Memon@cookcountyil.gov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Keith  - 


Doug 

From:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

Sent:  Tuesday,  June  23,  2020  6:20  AM 

To:  Douglas  Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov>:  Amar  Patel  (Sheriff) 
<Amar.Patel@cookcountyil.gov>:  Adnan  Memon  (Sheriff)  <Adnan.Memon@cookcountyil.gov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


Deputy  CIO  Maclean, 


Thanks, 


Morrison 


From:  Douglas  Maclean  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:10  AM 

To:  Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov>:  Keith  Morrison  (Sheriff) 
<Keith.Morrison@cookcountyil.gov>;  Adnan  Memon  (Sheriff)  <Adnan.Memon@cookcountyil.gov> 

Subject:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Krebs  on  Security  reports  Blue  Leaks  has  posted  24  years  of  LEA  and  fusion  center-related  data  as  the  result  of  a 
breach  on  Netsential,  an  internet  services  provider  to  LEAs  and  operational  fusion  centers.  The  data  includes  some 
information  related  to  sensitive  operations  and  a  significant  amount  of  Pll. 

The  Krebs  on  Security  story  can  be  found  here 

Keith  -  do  we  have  any  exposure  from  this  breach  either  directly  from  our  own  infrastructure  or  indirectly  as  the 
result  of  data-sharing  with  other  agencies?  Do  any  of  our  vendors  use  or  have  they  used  Netsential  for  any  of  their 
operations  from  1994  to  present? 


Douglas  MacLean 
Deputy  CIO 

Cook  County  Sheriffs  Office 
3026  S.  California 
South  Campus  Building  1 
Chicago  IL  60608 
312.877.2048  [c] 
773.674.8615  [d] 
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https://www.zdnet.com/article/blueleaks-data-from-200-us-police-departments-fusion-centers-published-online/ 

By  Catalin  Cimpanu 
Zero  Day 
ZDNet.com 
June  22,  2020 

An  activist  group  has  published  on  Friday  296  GB  of  data  they  claim  have  been 
stolen  from  US  law  enforcement  agencies  and  fusion  centers. 

The  files,  dubbed  BlueLeaks,  have  been  published  by  Distributed  Denial  of 
Secrets  (DDoSecrets),  a  group  that  describes  itself  as  a  "transparency 
collective." 

The  data  has  been  made  available  online  on  a  searchable  portal.  According  to  the 
BlueLeaks  portal,  the  leaked  data  contains  more  than  one  million  files,  such  as 
scanned  documents,  videos,  emails,  audio  files,  and  more. 

DDoSecrets  claims  the  leaked  files  contain  more  than  ten  years-worth  of  files 
belonging  to  more  than  200  police  departments  and  law  enforcement  fusion  centers 
from  across  the  US. 

[...] 
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By  Duncan  Riley 
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Microsoft  Corp.  has  acquired  industrial  cybersecurity  startup  CyberX  Inc.  for 
an  undisclosed  sum. 

Various  reports  today  suggest  that  the  acquisition  price  was  $1 65  million, 
following  initial  reports  of  the  deal  in  May. 


Founded  in  2013,  CyberX  offers  an  industrial  cybersecurity  platform  built  by 


former  military  cybersecurity  experts  with  nation-state  expertise  defending 
critical  infrastructure.  The  company?s  platform  focuses  on  continuously 
reducing  industrial  control  systems  risk  and  preventing  costly  production 
outages,  safety  failures  and  environmental  incidents. 

The  company?s  platform  works  by  mapping  out  all  connected  devices  in  a  factory 
or  corporate  network  to  give  administrators  a  high-level  view  of  potential 
risks.  CyberX  displays  unmanaged  systems  and  equipment  running  on  outdated 
firmware  as  well  as  detecting  malware.  Its  detection  algorithms  are  said  to 
spot  threats  by  looking  for  system  activity  that  deviates  from  a  device?s 
normal  behavior. 

CyberX?s  platform  integrates  with  customers?  existing  information  technology 
security  stacks,  including  Splunk,  IBM  Security,  Palo  Alto  Networks,  Cisco 
Systems,  RSA  NetWitness  and  ServiceNow. 
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A  House  Armed  Services  Committee  draft  of  the  annual  defense  policy  bill  calls 
for  the  National  Guard  and  Reserve  components  to  assist  in  defending  the  nation 
in  cyberspace. 

A  provision  in  the  bill?s  markup  from  the  Subcommittee  on  Intelligence  and 
Emerging  Threats  and  Capabilities,  which  passed  the  committee  June  22,  requires 
a  review  of  statues  and  rules  that  pertain  to  the  use  of  the  National  Guard  for 
response  and  recovery  from  significant  cyberattacks. 

The  bill  defines  a  cyber  incident  as  significant  if  the  event  results  in 
demonstrable  harm  to  the  national  security  interests  or  economy  of  the  United 
States  and  the  public  confidence,  civil  liberties,  or  public  health  and  safety 
of  the  American  people. 


A  separate  provision  in  the  bill  requires  an  evaluation  of  nontraditional  cyber 
support  to  the  Department  of  Defense.  The  assessment  will  include  an  evaluation 
of  Reserve  and  Guard  support  to  cyber  operations  forces;  an  evaluation  of 
various  Reserve,  Guard,  auxiliary  and  nontraditional  support  models  to  include 
those  that  can  be  utilized  domestically  and  internationally;  and  an  evaluation 
of  dedicated  reserve  components  specific  to  U.S.  Cyber  Command. 
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By  Shannon  Vavra 
CYBERSCOOP 
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In  his  new  book,  former  national  security  adviser  John  Bolton  says  that 
squabbling  amongst  Trump  administration  officials  hobbled  the  White  House?s 
efforts  to  issue  new  policies  that  shaped  the  U.S.  government?s  offensive  and 
defense  cyber-operations. 

The  book,  ?The  Room  Where  It  Happened:  A  White  House  Memoir,?  which  CyberScoop 
obtained,  provides  an  insider?s  view  of  the  U.S.  government?s  largely  secretive 
approach  to  revamping  cyber  policy  in  the  last  two  years.  Aside  from 
cyber-operations,  Bolton  paints  President  Donald  Trump  as  preoccupied  and 
angered  by  cybersecurity-related  issues,  as  well  as  all  too  willing  to  use 
hacking  to  prop  up  his  political  goals  in  negotiations  with  China  and  Ukraine. 

?We  needed  to  do  two  things:  first,  we  needed  a  Trump  Administration  cyber 
strategy,  and  second,  we  needed  to  scrap  the  Obama-era  [offensive 
cyber-operations]  rules  and  replace  them  with  a  more  agile,  expeditious 
decision-making  structure,?  Bolton  writes  of  his  time  negotiating  new  policies 
with  national  security  and  intelligence  officials  in  2018.  ?Unfortunately, 
bureaucratic  inertia,  turf  fights,  and  some  genuine  unresolved  issues  paralyzed 
the  Trump  Administration,  month  after  month.? 

Bolton  writes  that  the  Obama  administration?s  approach  to  fending  off  hacking 
from  China,  Russia,  Iran,  and  North  Korea  had  been  criticized  for  not  being 
aggressive  enough.  In  order  to  better  deter  them,  the  Trump  administration  had 
set  its  sights  on  giving  U.S.  military  hackers  more  leeway  to  hit  back. 
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By  Anthony  Galloway 
Sydney  Morning  Herald 
June  23,2020 

Australia  and  the  United  States  have  been  urged  to  jointly  name  and  shame 
state-backed  actors  looking  to  steal  health  research  during  the  coronavirus 
pandemic,  as  the  Morrison  government  battles  an  escalation  in  cyber  attacks  on 
key  networks. 

In  a  paper  to  be  published  by  the  United  States  Studies  Centre  at  the 
University  of  Sydney  on  Tuesday,  five  foreign  policy  experts  also  say  the  two 
countries  should  strengthen  their  ability  to  counter  disinformation  campaigns 
as  an  urgent  priority  in  light  of  China's  use  of  such  tactics  during  COVID-19. 

Australian  security  agencies  believe  China  is  responsible  for  a  wave  of  cyber 
attacks  against  the  NSW  government  and  other  critical  Australian  infrastructure 
including  state-owned  utilities  and  hospitals  but  the  Morrison  government  has 
chosen  not  to  name  the  country  involved. 

While  China  has  denied  it  is  behind  the  Australian  attacks,  the  US  recently 
warned  Beijing's  most  skilled  hackers  and  spies  were  working  to  steal  American 
research  to  develop  vaccines  and  treatments  for  COVID-19. 
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Lexipol.  2611  Internet  Blvd.,  Ste.  100,  Frisco,  TX  75034. 


FW:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers 
Affected  by  #BlueLeaks  Data  Breach  -  TLP:  AMBER 

From:  Jonathan  Springborn  (Sheriff)  </0=EXCHANGELABS/OU=EXCHANGE 

ADMINISTRATIVE  GROUP 

(FYDIBOHF23SPDLT)/CN=RECIPIENTS/CN=32F2AOA9AA124C638CA1784E3422B46 
4-JONATHAN  SP> 

To:  Keith  Morrison  (Keith.Morrison@cookcountyil.gov)  <Keith.Morrison@cookcountyil.gov>, 

Patrick  Kelly  (Sheriff)  <Patrick.Kelly@cookcountyil.gov>,  Christopher  Moore  (Sheriff) 
<Christopher.Moore@cookcountyil.gov> 

Sent:  June  23,  2020  4:27:34  PM  CDT 

Received:  June  23,  2020  4:27:00  PM  CDT 

FYI, 

You  may  want  to  check  out  this  alert  and  URL. 


Data  breach  affected:  Illinois  Crime  Reporting  and  Information  -  Metro  East 


https://www.bleepingcomputer.com/news/securitv/blueleaks-data-dump-exposes-over-24-years-of-police-records/ 


Jonathan  Springborn 
Jonathan.Springborn@cookcountyil.gov 

(773)674-6850 -Helpdesk 
(773)674-7762  -  Office  Desk  Phone 


From:  MS-ISAC  Advisory  <MS-ISAC.Advisory@msisac.org> 

Sent:  Tuesday,  June  23,  2020  11:04  AM 

To:  Michael  Aliperti  <Michael.Aliperti@cisecurity.org>;  Ben  Spear  <Ben.Spear@cisecurity.org> 

Subject:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data 
Breach -TLP:  AMBER 


External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 


TLP:  AMBER 


TO:  All  MS-ISAC  Members  and  Partners 
DATE:  June  23,  2020 

SUBJECT:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data  Breach 

On  June  1 9,  2020,  a  Twitter  account  announced  the  leak  of  1 0  years  of  data  from  police  departments, 
fusion  centers,  and  other  law  enforcement-related  entities  currently  being  tracked  on  social  media  as 
#BlueLeaks.  According  to  the  National  Fusion  Center  Association  (NFCA),  the  leak  is  the  result  of  a 
compromise  at  a  third  party  web  hosting  company,  Netsential. 

The  Twitter  account  is  associated  with  Distributed  Denial  of  Secrets  (DDOS),  a  collective  known  for  posting 
leaked  or  exfiltrated  data.  The  post  included  a  link  to  a  Dark  Web  location  hosting  269GB  of  files  and 
emails  including  bulletins,  advisories,  and  guides. 

Upon  receiving  notification  of  this  data  breach,  the  MS-ISAC  has  confirmed  the  existence  of  the  dataset 
and  is  currently  working  to  analyze  the  specific  contents  of  the  data  along  with  our  federal,  state,  and  local 


partners.  At  this  time,  some  MS-ISAC  products  and  correspondence  have  been  identified  in  the  leaked  data 
due  to  the  nature  of  our  relationship  with  fusion  centers  and  law  enforcement  entities.  It  is  likely  that  cyber 
threat  actors  will  utilize  MS-ISAC  information  and/or  other  portions  of  the  data  dump  to  create  tailored 
phishing  campaigns  or  conduct  other  malicious  cyber  activity. 

Recommendations: 

•  Be  vigilant  for  new  waves  of  phishing  campaigns  spoofing  emails  or  products. 

•  Implement  Sender  Policy  Framework  (SPF),  Domain  Keys  Identified  Mail  (DKIM),  and  Domain- 
Based  Message  Authentication  Reporting  and  Conformance  (DMARC),  which  will  assist  in  ensuring 
that  senders  are  unable  to  spoof  your  email  domain.  For  assistance  in  implementing  these  controls, 
see  the  Global  Cyber  Alliance’s  DMARC  Guide  https://dmarcquide.qlobalcvberalliance.Org/#/. 

•  Ensure  anti-virus  software  is  up  to  date. 

•  Remind  users  not  to  visit  un-trusted  websites  or  follow  links  provided  by  unknown  or  un-trusted 
sources. 

•  Apply  the  Principle  of  Least  Privilege  to  all  systems  and  services. 

The  MS-ISAC  continues  to  monitor  this  situation  closely  and  will  release  further  information  as  appropriate. 
24x7  Security  Operations  Center 

Multi-State  Information  Sharing  and  Analysis  Center  (MS-ISAC) 

Elections  Infrastructure  Information  Sharing  and  Analysis  Center  (EI-ISAC) 

31  Tech  Valley  Drive 
East  Greenbush,  NY  12061 
SOC@cisecurity.org  -  1-866-787-4722 

®  MS-ISAC’  ik  Infrastructure 

I  SAC 

OOOO 


TLP:  AMBER 

Limited  Disclosure,  restricted  to  participants'  organizations.  Recipients  may  only  share  TLP: 
AMBER  information  with  members  of  their  own  organization,  and  with  clients  or  customers  who 
need  to  know  the  information  to  protect  themselves  or  prevent  further  harm. 

http://www.us-cert.gov/tlp/ 

This  message  and  attachments  may  contain  confidential  information.  If  it  appears  that  this  message  was  sent  to  you 
by  mistake,  any  retention,  dissemination,  distribution  or  copying  of  this  message  and  attachments  is  strictly 
prohibited.  Please  notify  the  sender  immediately  and  permanently  delete  the  message  and  any  attachments. 


RE:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers 
Affected  by  #BlueLeaks  Data  Breach  -  TLP:  AMBER 

From:  Patrick  Kelly  (Sheriff)  </0=EXCHANGELABS/OU=EXCHANGE  ADMINISTRATIVE 

GROUP 

(FYDIBOHF23SPDLT)/CN=RECIPIENTS/CN=873FFD393E8C44B79E707E6A1 056650 
A-PATRICK  KEL> 

To:  Jonathan  Springborn  (Sheriff)  <Jonathan.Springborn@cookcountyil.gov>,  Keith  Morrison 

(Sheriff)  <Keith.Morrison@cookcountyil.gov>,  Christopher  Moore  (Sheriff) 
<Christopher.Moore@cookcountyil.gov> 

Sent:  June  23,  2020  4:35:19  PM  CDT 

Received:  June  23,  2020  4:35:00  PM  CDT 

Wow.. .that  is  crazy.  Not  good  at  all. 


From:  Jonathan  Springborn  (Sheriff)  <Jonathan.Springborn@cookcountyil.gov> 

Sent:  Tuesday,  June  23,  2020  4:28  PM 

To:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov>;  Patrick  Kelly  (Sheriff) 
<Patrick.Kelly@cookcountyil.gov>;  Christopher  Moore  (Sheriff)  <Christopher.Moore@cookcountyil.gov> 

Subject:  FW:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data 
Breach -TLP:  AMBER 
Importance:  High 

FYI, 

You  may  want  to  check  out  this  alert  and  URL. 


Data  breach  affected:  Illinois  Crime  Reporting  and  Information  -  Metro  East 


https://www.bleepingcomputer.com/news/securitv/blueleaks-data-dump-exposes-over-24-years-of-police-records/ 


Jonathan  Springborn 
Jonathan.Springbom@cookcountyil.gov 

(773)674-6850 -Helpdesk 
(773)674-7762  -  Office  Desk  Phone 


From:  MS-ISAC  Advisory  <MS-ISAC.Advisorv@msisac.org> 

Sent:  Tuesday,  June  23,  2020  11:04  AM 

To:  Michael  Aliperti  <Michael.Aliperti@cisecurity.org>:  Ben  Spear  <Ben.Spear@cisecuritv.org> 

Subject:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data 
Breach -TLP:  AMBER 


External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 

TLP:  AMBER 

TO:  All  MS-ISAC  Members  and  Partners 
DATE:  June  23,  2020 


SUBJECT:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data  Breach 

On  June  19,  2020,  a  Twitter  account  announced  the  leak  of  10  years  of  data  from  police  departments, 
fusion  centers,  and  other  law  enforcement-related  entities  currently  being  tracked  on  social  media  as 
#BlueLeaks.  According  to  the  National  Fusion  Center  Association  (NFCA),  the  leak  is  the  result  of  a 
compromise  at  a  third  party  web  hosting  company,  Netsential. 

The  Twitter  account  is  associated  with  Distributed  Denial  of  Secrets  (DDOS),  a  collective  known  for  posting 
leaked  or  exfiltrated  data.  The  post  included  a  link  to  a  Dark  Web  location  hosting  269GB  of  files  and 
emails  including  bulletins,  advisories,  and  guides. 

Upon  receiving  notification  of  this  data  breach,  the  MS-ISAC  has  confirmed  the  existence  of  the  dataset 
and  is  currently  working  to  analyze  the  specific  contents  of  the  data  along  with  our  federal,  state,  and  local 
partners.  At  this  time,  some  MS-ISAC  products  and  correspondence  have  been  identified  in  the  leaked  data 
due  to  the  nature  of  our  relationship  with  fusion  centers  and  law  enforcement  entities.  It  is  likely  that  cyber 
threat  actors  will  utilize  MS-ISAC  information  and/or  other  portions  of  the  data  dump  to  create  tailored 
phishing  campaigns  or  conduct  other  malicious  cyber  activity. 

Recommendations: 

•  Be  vigilant  for  new  waves  of  phishing  campaigns  spoofing  emails  or  products. 

•  Implement  Sender  Policy  Framework  (SPF),  Domain  Keys  Identified  Mail  (DKIM),  and  Domain- 
Based  Message  Authentication  Reporting  and  Conformance  (DMARC),  which  will  assist  in  ensuring 
that  senders  are  unable  to  spoof  your  email  domain.  For  assistance  in  implementing  these  controls, 
see  the  Global  Cyber  Alliance’s  DMARC  Guide  https://dmarcquide.qlobalcvberalliance.Org/#/. 

•  Ensure  anti-virus  software  is  up  to  date. 

•  Remind  users  not  to  visit  un-trusted  websites  or  follow  links  provided  by  unknown  or  un-trusted 
sources. 

•  Apply  the  Principle  of  Least  Privilege  to  all  systems  and  services. 

The  MS-ISAC  continues  to  monitor  this  situation  closely  and  will  release  further  information  as  appropriate. 
24x7  Security  Operations  Center 

Multi-State  Information  Sharing  and  Analysis  Center  (MS-ISAC) 

Elections  Infrastructure  Information  Sharing  and  Analysis  Center  (EI-ISAC) 

31  Tech  Valley  Drive 
East  Greenbush,  NY  12061 
SOC@cisecurity.org  -  1-866-787-4722 

©  MS-ISAC-  £  infrastructure 

I  SAC 

ooo© 


TLP:  AMBER 

Limited  Disclosure,  restricted  to  participants'  organizations.  Recipients  may  only  share  TLP: 
AMBER  information  with  members  of  their  own  organization,  and  with  clients  or  customers  who 
need  to  know  the  information  to  protect  themselves  or  prevent  further  harm. 

http://www.us-cert.gov/tlp/ 

This  message  and  attachments  may  contain  confidential  information.  If  it  appears  that  this  message  was  sent  to  you 
by  mistake,  any  retention,  dissemination,  distribution  or  copying  of  this  message  and  attachments  is  strictly 
prohibited.  Please  notify  the  sender  immediately  and  permanently  delete  the  message  and  any  attachments. 


RE:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers 
Affected  by  #BlueLeaks  Data  Breach  -  TLP:  AMBER 

From:  Jonathan  Springborn  (Sheriff)  </0=EXCHANGELABS/OU=EXCHANGE 

ADMINISTRATIVE  GROUP 

(FYDIBOHF23SPDLT)/CN=RECIPIENTS/CN=32F2AOA9AA124C638CA1784E3422B46 
4-JONATHAN  SP> 

To:  Patrick  Kelly  (Sheriff)  <Patrick.Kelly@cookcountyil.gov>,  Keith  Morrison  (Sheriff) 

<Keith.Morrison@cookcountyil.gov>,  Christopher  Moore  (Sheriff) 
<Christopher.Moore@cookcountyil.gov> 

Sent:  June  23,  2020  4:38:23  PM  CDT 

Received:  June  23,  2020  4:38:00  PM  CDT 

Agreed. 

I  found  these  entities  close  to  us  that  were  affected: 


Wisconsin  Statewide  Intelligence  Center 
FBI  National  Academy  Association  Michigan  Chapter 
Iowa  Law  Enforcement  Academy 
Iowa  Fusion  Center 
Missouri  Information  Analysis  Center 
I  don't  know  if  we  interact  much  if  at  all,  but  they  are  close  by. 


Jonathan  Springborn 
Jonathan.Springborn@cookcountyil.gov 

(773)674-6850 -Helpdesk 
(773)674-7762  -  Office  Desk  Phone 


From:  Patrick  Kelly  (Sheriff)  <Patrick.Kelly@cookcountyil.gov> 

Sent:  Tuesday,  June  23,  2020  4:35  PM 

To:  Jonathan  Springborn  (Sheriff)  <Jonathan.Springborn@cookcountyil.gov>;  Keith  Morrison  (Sheriff) 
<Keith.Morrison@cookcountyil.gov>;  Christopher  Moore  (Sheriff)  <Christopher.Moore@cookcountyil.gov> 
Subject:  RE:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data 
Breach -TLP:  AMBER 


Wow.. .that  is  crazy.  Not  good  at  all. 


From:  Jonathan  Springborn  (Sheriff)  <Jonathan.Springborn@cookcountyil.gov> 

Sent:  Tuesday,  June  23,  2020  4:28  PM 

To:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov>:  Patrick  Kelly  (Sheriff) 
<Patrick.Kellv@cookcountyil.gov>:  Christopher  Moore  (Sheriff)  <Christopher.Moore@cookcountyil.gov> 

Subject:  FW:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data 
Breach -TLP:  AMBER 
Importance:  High 


FYI, 

You  may  want  to  check  out  this  alert  and  URL. 


Data  breach  affected:  Illinois  Crime  Reporting  and  Information  -  Metro  East 


https://www.bleepingcomputer.com/news/securitv/blueleaks-data-dump-exposes-over-24-years-of-police-records/ 


Jonathan  Springborn 
Jonathan.Springborn@cookcountyil.gov 

(773)674-6850 -Helpdesk 
(773)674-7762  -  Office  Desk  Phone 


From:  MS-ISAC  Advisory  <MS-ISAC.Advisory@msisac.org> 

Sent:  Tuesday,  June  23,  2020  11:04  AM 

To:  Michael  Aliperti  <Michael.Aliperti@cisecurity.org>;  Ben  Spear  <Ben.Spear@cisecurity.org> 

Subject:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data 
Breach -TLP:  AMBER 


External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 


TLP:  AMBER 


TO:  All  MS-ISAC  Members  and  Partners 
DATE:  June  23,  2020 

SUBJECT:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data  Breach 

On  June  1 9,  2020,  a  Twitter  account  announced  the  leak  of  1 0  years  of  data  from  police  departments, 
fusion  centers,  and  other  law  enforcement-related  entities  currently  being  tracked  on  social  media  as 
#BlueLeaks.  According  to  the  National  Fusion  Center  Association  (NFCA),  the  leak  is  the  result  of  a 
compromise  at  a  third  party  web  hosting  company,  Netsential. 

The  Twitter  account  is  associated  with  Distributed  Denial  of  Secrets  (DDOS),  a  collective  known  for  posting 
leaked  or  exfiltrated  data.  The  post  included  a  link  to  a  Dark  Web  location  hosting  269GB  of  files  and 
emails  including  bulletins,  advisories,  and  guides. 

Upon  receiving  notification  of  this  data  breach,  the  MS-ISAC  has  confirmed  the  existence  of  the  dataset 
and  is  currently  working  to  analyze  the  specific  contents  of  the  data  along  with  our  federal,  state,  and  local 
partners.  At  this  time,  some  MS-ISAC  products  and  correspondence  have  been  identified  in  the  leaked  data 
due  to  the  nature  of  our  relationship  with  fusion  centers  and  law  enforcement  entities.  It  is  likely  that  cyber 
threat  actors  will  utilize  MS-ISAC  information  and/or  other  portions  of  the  data  dump  to  create  tailored 
phishing  campaigns  or  conduct  other  malicious  cyber  activity. 

Recommendations: 

•  Be  vigilant  for  new  waves  of  phishing  campaigns  spoofing  emails  or  products. 

•  Implement  Sender  Policy  Framework  (SPF),  Domain  Keys  Identified  Mail  (DKIM),  and  Domain- 
Based  Message  Authentication  Reporting  and  Conformance  (DMARC),  which  will  assist  in  ensuring 
that  senders  are  unable  to  spoof  your  email  domain.  For  assistance  in  implementing  these  controls, 
see  the  Global  Cyber  Alliance’s  DMARC  Guide  https://dmarcquide.qlobalcvberalliance.Org/#/. 

•  Ensure  anti-virus  software  is  up  to  date. 

•  Remind  users  not  to  visit  un-trusted  websites  or  follow  links  provided  by  unknown  or  un-trusted 
sources. 

•  Apply  the  Principle  of  Least  Privilege  to  all  systems  and  services. 


The  MS-ISAC  continues  to  monitor  this  situation  closely  and  will  release  further  information  as  appropriate. 


24x7  Security  Operations  Center 

Multi-State  Information  Sharing  and  Analysis  Center  (MS-ISAC) 

Elections  Infrastructure  Information  Sharing  and  Analysis  Center  (EI-ISAC) 
31  Tech  Valley  Drive 
East  Greenbush,  NY  12061 
SOC@cisecurity.org  -  1-866-787-4722 

©  MS-ISAC-  £  fnfras^ructure 

I  SAC 

oooo 


TLP:  AMBER 

Limited  Disclosure,  restricted  to  participants'  organizations.  Recipients  may  only  share  TLP: 
AMBER  information  with  members  of  their  own  organization,  and  with  clients  or  customers  who 
need  to  know  the  information  to  protect  themselves  or  prevent  further  harm. 

http://www.us-cert.gov/tlp/ 

This  message  and  attachments  may  contain  confidential  information.  If  it  appears  that  this  message  was  sent  to  you 
by  mistake,  any  retention,  dissemination,  distribution  or  copying  of  this  message  and  attachments  is  strictly 
prohibited.  Please  notify  the  sender  immediately  and  permanently  delete  the  message  and  any  attachments. 


RE:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers 
Affected  by  #BlueLeaks  Data  Breach  -  TLP:  AMBER 

To:  Jonathan  Springborn  (Sheriff)  <Jonathan.Springborn@cookcountyil.gov>,  Keith 

Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov>,  Christopher  Moore 
(Sheriff)  <Christopher.Moore@cookcountyil.gov> 

Sent:  June  23,  2020  4:42:33  PM  CDT 

Received:  June  23,  2020  4:42:21  PM  CDT 

Yeah.  I  saw  Infragard  (San  Francisco)  is  one  of  them. 


From:  Jonathan  Springborn  (Sheriff)  <Jonathan.Springborn@cookcountyil.gov> 

Sent:  Tuesday,  June  23,  2020  4:38  PM 

To:  Patrick  Kelly  (Sheriff)  <Patrick.Kelly@cookcountyil.gov>;  Keith  Morrison  (Sheriff) 
<Keith.Morrison@cookcountyil.gov>;  Christopher  Moore  (Sheriff)  <Christopher.Moore@cookcountyil.gov> 
Subject:  RE:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data 
Breach -TLP:  AMBER 


Agreed. 

I  found  these  entities  close  to  us  that  were  affected: 

Wisconsin  Statewide  Intelligence  Center 
FBI  National  Academy  Association  Michigan  Chapter 
Iowa  Law  Enforcement  Academy 
Iowa  Fusion  Center 
Missouri  Information  Analysis  Center 
I  don't  know  if  we  interact  much  if  at  all,  but  they  are  close  by. 


Jonathan  Springborn 
Jonathan.Springbom@cookcountyil.gov 

(773)674-6850 -Helpdesk 
(773)674-7762  -  Office  Desk  Phone 


From:  Patrick  Kelly  (Sheriff)  <Patrick.Kellv@cookcountyil.gov> 

Sent:  Tuesday,  June  23,  2020  4:35  PM 

To:  Jonathan  Springborn  (Sheriff)  <Jonathan.Springborn@cookcountyil.gov>:  Keith  Morrison  (Sheriff) 
<Keith.Morrison@cookcountyil.gov>:  Christopher  Moore  (Sheriff)  <Christopher.Moore@cookcountyil.gov> 
Subject:  RE:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data 
Breach -TLP:  AMBER 


Wow.. .that  is  crazy.  Not  good  at  all. 


From:  Jonathan  Springborn  (Sheriff)  <Jonathan.Springborn@cookcountvil.gov> 

Sent:  Tuesday,  June  23,  2020  4:28  PM 

To:  Keith  Morrison  (Sheriff)  <Keith. Morrison@cookcountyil.gov>:  Patrick  Kelly  (Sheriff) 
<Patrick.Kellv@cookcountyil.gov>:  Christopher  Moore  (Sheriff)  <Christopher. Moore@cookcountyil.gov> 

Subject:  FW:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data 


Breach -TLP:  AMBER 
Importance:  High 


FYI, 

You  may  want  to  check  out  this  alert  and  URL 
Data  breach  affected:  Illinois  Crime  Reporting  and  Information  -  Metro  East 


https://www.bleepingcomputer.com/news/securitv/blueleaks-data-dump-exposes-over-24-years-of-police-records/ 


Jonathan  Springborn 
Jonathan.Springborn@cookcountyil.gov 

(773)674-6850 -Helpdesk 
(773)674-7762  -  Office  Desk  Phone 


From:  MS-ISAC  Advisory  <MS-ISAC.Advisory@msisac.org> 

Sent:  Tuesday,  June  23,  2020  11:04  AM 

To:  Michael  Aliperti  <Michael.Aliperti@dsecurity.org>:  Ben  Spear  <Ben.Spear@cisecurity.org> 

Subject:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data 
Breach -TLP:  AMBER 


External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 


TLP:  AMBER 


TO:  All  MS-ISAC  Members  and  Partners 
DATE:  June  23,  2020 

SUBJECT:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data  Breach 

On  June  1 9,  2020,  a  Twitter  account  announced  the  leak  of  1 0  years  of  data  from  police  departments, 
fusion  centers,  and  other  law  enforcement-related  entities  currently  being  tracked  on  social  media  as 
#BlueLeaks.  According  to  the  National  Fusion  Center  Association  (NFCA),  the  leak  is  the  result  of  a 
compromise  at  a  third  party  web  hosting  company,  Netsential. 

The  Twitter  account  is  associated  with  Distributed  Denial  of  Secrets  (DDOS),  a  collective  known  for  posting 
leaked  or  exfiltrated  data.  The  post  included  a  link  to  a  Dark  Web  location  hosting  269GB  of  files  and 
emails  including  bulletins,  advisories,  and  guides. 

Upon  receiving  notification  of  this  data  breach,  the  MS-ISAC  has  confirmed  the  existence  of  the  dataset 
and  is  currently  working  to  analyze  the  specific  contents  of  the  data  along  with  our  federal,  state,  and  local 
partners.  At  this  time,  some  MS-ISAC  products  and  correspondence  have  been  identified  in  the  leaked  data 
due  to  the  nature  of  our  relationship  with  fusion  centers  and  law  enforcement  entities.  It  is  likely  that  cyber 
threat  actors  will  utilize  MS-ISAC  information  and/or  other  portions  of  the  data  dump  to  create  tailored 
phishing  campaigns  or  conduct  other  malicious  cyber  activity. 

Recommendations: 

•  Be  vigilant  for  new  waves  of  phishing  campaigns  spoofing  emails  or  products. 

•  Implement  Sender  Policy  Framework  (SPF),  Domain  Keys  Identified  Mail  (DKIM),  and  Domain- 
Based  Message  Authentication  Reporting  and  Conformance  (DMARC),  which  will  assist  in  ensuring 


that  senders  are  unable  to  spoof  your  email  domain.  For  assistance  in  implementing  these  controls, 
see  the  Global  Cyber  Alliance’s  DMARC  Guide  https://dmarcquide.qlobalcvberalliance.Org/#/. 

•  Ensure  anti-virus  software  is  up  to  date. 

•  Remind  users  not  to  visit  un-trusted  websites  or  follow  links  provided  by  unknown  or  un-trusted 
sources. 

•  Apply  the  Principle  of  Least  Privilege  to  all  systems  and  services. 

The  MS-ISAC  continues  to  monitor  this  situation  closely  and  will  release  further  information  as  appropriate. 
24x7  Security  Operations  Center 

Multi-State  Information  Sharing  and  Analysis  Center  (MS-ISAC) 

Elections  Infrastructure  Information  Sharing  and  Analysis  Center  (EI-ISAC) 

31  Tech  Valley  Drive 
East  Greenbush,  NY  12061 
SOC@cisecuritv.org  -  1-866-787-4722 
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TLP:  AMBER 

Limited  Disclosure,  restricted  to  participants'  organizations.  Recipients  may  only  share  TLP: 
AMBER  information  with  members  of  their  own  organization,  and  with  clients  or  customers  who 
need  to  know  the  information  to  protect  themselves  or  prevent  further  harm. 

http://www.us-cert.gov/tlp/ 

This  message  and  attachments  may  contain  confidential  information.  If  it  appears  that  this  message  was  sent  to  you 
by  mistake,  any  retention,  dissemination,  distribution  or  copying  of  this  message  and  attachments  is  strictly 
prohibited.  Please  notify  the  sender  immediately  and  permanently  delete  the  message  and  any  attachments. 


RE:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers 
Affected  by  #BlueLeaks  Data  Breach  -  TLP:  AMBER 

To:  Jonathan  Springborn  (Sheriff),  Keith  Morrison  (Sheriff),  Christopher  Moore  (Sheriff) 

Sent:  June  23,  2020  4:42:33  PM  CDT 

Received:  June  23,  2020  4:42:21  PM  CDT 


Man  Saves  Officer  from  Wrecked  Patrol  Car 


From:  Police  On  Target  <PoliceOnTarget@bobitenews.com> 

To:  edward.lewandowski@cookcountyil.gov,  Edward  Lewandowski  (Sheriff) 

<Edward. Lewandowski@cookcountyil.gov> 

Sent:  June  23,  2020  5:23:28  PM  CDT 

Received:  June  23,  2020  5:23:31  PM  CDT 


External  Message  Disclaimer 


This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 
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View  online  version 


ONTARGET  TUESDAY 


Pennsylvania  Man  Pulls  Police 
Officer  from  Wrecked  Patrol  Car 

Daylan  McLee  was  at  a  Fathers'  Day  event  with 
family  when  he  saw  the  police  officer  pinned  to  the 
ground  by  his  patrol  vehicle  following  a  crash. 

READ  MORE 


Hackers  Steals  Massive  Trove  of  Police  Files,  Post  Them 
Online 

DDoSecrets  said  the  BlueLeaks  archive  indexes  “ten  years  of  data  from  over  200 
police  departments,  fusion  centers  and  other  law  enforcement  training  and  support 
resources,”  and  that  “among  the  hundreds  of  thousands  of  documents  are  police  and 
FBI  reports,  bulletins,  guides  and  more.” 

READ  MORE 


■  Florida  Officers  Lured  Into  Ambush 
Attack  at  Call  for  Service 

Several  officers  with  the  Tampa  (LF)  Police 
Department  were  reportedly  ambushed  early 
Saturday  morning  while  responding  to  a  call  for 
service. 

READ  MORE 


Maryland  Officer  Wounded  by 
Gunfire  Released  from  Hospital 


An  officer  with  the  Baltimore  Police  Department  who 
was  shot  earlier  this  month  while  he  tried  to  disperse 
a  large  crowd  that  had  gathered  to  protest  the  in- 
custody  death  of  George  Floyd  in  Minneapolis  has 
been  released  from  the  hospital. 


READ  MORE 


Responding  to  Domestic 
Disturbances 

A  domestic  disturbance  call  can  involve  anything  from 


■  a  verbal  dispute  to  a  homicide.  So  we  all  need 

reminders  of  the  danger  of  domestic  disputes  and 
ensure  officers  are  taking  all  precautions. 

READ  MORE 


Massachusetts  Officer  Injured  in  Attack  During  Interview  at 
Police  Station 

An  officer  with  the  Southborough  (MA)  Police  Department  was  injured  after  he  was 
reportedly  assaulted  with  a  weapon  inside  a  police  station  on  Monday  night. 

READ  MORE 


Oregon  Officer  Saves  Infant  from  Burning  Home 

An  officer  with  the  Astoria  (OR)  Police  Department  is  being  heralded  as  a  hero  for  his 
quick  actions  late  last  week  that  are  now  only  becoming  public  knowledge. 

READ  MORE 


Texas  Officer  Shot  in  Arm  Following  Vehicle  and  Foot 
Pursuit 

An  officer  with  the  Watauga  (TX)  Police  Department  was  shot  in  the  arm  by  a  suspect 
who  led  police  on  a  vehicle  chase,  bailed  out  of  the  car  and  ran  away,  briefly  eluding 
officers. 

READ  MORE 


Hybrids  Ready  for  Patrol 

Police  vehicles  with  hybrid  gas-electric  engines  will 
save  law  enforcement  agencies  money  and  cut 


emissions.  More  importantly,  they  can  do  the  job. 


READ  MORE 
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From:  Police  On  Target  <PoliceOnTarget@bobitenews.com> 

To:  larry.schurig@cookcountyil.gov,  Larry  Schurig  (Sheriff) 

<Larry.Schurig@cookcountyil.gov> 

Sent:  June  23,  2020  5:24:40  PM  CDT 
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Daylan  McLee  was  at  a  Fathers'  Day  event  with 
family  when  he  saw  the  police  officer  pinned  to  the 
ground  by  his  patrol  vehicle  following  a  crash. 
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Hackers  Steals  Massive  Trove  of  Police  Files,  Post  Them 
Online 

DDoSecrets  said  the  BlueLeaks  archive  indexes  “ten  years  of  data  from  over  200 
police  departments,  fusion  centers  and  other  law  enforcement  training  and  support 
resources,”  and  that  “among  the  hundreds  of  thousands  of  documents  are  police  and 
FBI  reports,  bulletins,  guides  and  more.” 

READ  MORE 


■  Florida  Officers  Lured  Into  Ambush 
Attack  at  Call  for  Service 

Several  officers  with  the  Tampa  (LF)  Police 
Department  were  reportedly  ambushed  early 
Saturday  morning  while  responding  to  a  call  for 
service. 
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Maryland  Officer  Wounded  by 
Gunfire  Released  from  Hospital 


An  officer  with  the  Baltimore  Police  Department  who 
was  shot  earlier  this  month  while  he  tried  to  disperse 
a  large  crowd  that  had  gathered  to  protest  the  in- 
custody  death  of  George  Floyd  in  Minneapolis  has 
been  released  from  the  hospital. 
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Responding  to  Domestic 
Disturbances 

A  domestic  disturbance  call  can  involve  anything  from 


■  a  verbal  dispute  to  a  homicide.  So  we  all  need 

reminders  of  the  danger  of  domestic  disputes  and 
ensure  officers  are  taking  all  precautions. 
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Massachusetts  Officer  Injured  in  Attack  During  Interview  at 
Police  Station 

An  officer  with  the  Southborough  (MA)  Police  Department  was  injured  after  he  was 
reportedly  assaulted  with  a  weapon  inside  a  police  station  on  Monday  night. 
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Oregon  Officer  Saves  Infant  from  Burning  Home 

An  officer  with  the  Astoria  (OR)  Police  Department  is  being  heralded  as  a  hero  for  his 
quick  actions  late  last  week  that  are  now  only  becoming  public  knowledge. 

READ  MORE 


Texas  Officer  Shot  in  Arm  Following  Vehicle  and  Foot 
Pursuit 

An  officer  with  the  Watauga  (TX)  Police  Department  was  shot  in  the  arm  by  a  suspect 
who  led  police  on  a  vehicle  chase,  bailed  out  of  the  car  and  ran  away,  briefly  eluding 
officers. 
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resources,”  and  that  “among  the  hundreds  of  thousands  of  documents  are  police  and 
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An  officer  with  the  Southborough  (MA)  Police  Department  was  injured  after  he  was 
reportedly  assaulted  with  a  weapon  inside  a  police  station  on  Monday  night. 

READ  MORE 


Oregon  Officer  Saves  Infant  from  Burning  Home 

An  officer  with  the  Astoria  (OR)  Police  Department  is  being  heralded  as  a  hero  for  his 
quick  actions  late  last  week  that  are  now  only  becoming  public  knowledge. 

READ  MORE 


Texas  Officer  Shot  in  Arm  Following  Vehicle  and  Foot 
Pursuit 
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From:  A  BUNTINAS  <lietuvis_75@hotmail.com> 

To:  Arunas  Buntinas  <arunas.buntinas2@cookcountyil.gov>,  Arunas  Buntinas 

(Sheriff)  <Arunas. Buntinas2@cookcountyil.gov> 
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Group  Posts  269  GB  of  Data  Stolen  from  US  Law  Enforcement  Databases 

(June  22,  2020) 

A  group  calling  itself  Distributed  Denial  of  Secrets  has  posted  269  gigabytes  of  police  data  online.  According  to  a 
memo  from  the  National  Fusion  Center  Association  obtained  by  Brian  Krebs,  the  data  were  taken  from  state  owned 
and  operated  law  enforcement  fusion  centers,  which  serve  to  coordinate  communications  between  state,  local, 
federal,  tribal,  territorial,  private  law  enforcement  partners.  The  memo  notes  that  “Preliminary  analysis  of  the  data 
contained  in  this  leak  suggests  that  Netsential,  a  web  services  company  used  by  multiple  fusion  centers,  law 
enforcement,  and  other  government  agencies  across  the  United  States,  was  the  source  of  the  compromise.” 

Read  more  in: 

-  krebsonsecuritv.com:  ‘BlueLeaks’  Exposes  Files  from  Hundreds  of  Police  Departments 

-  arstechnica.com:  Millions  of  documents  from  >200  US  police  agencies  published  in  “BlueLeaks”  trove 

-  www.wired.com:  Hack  Brief:  Anonymous  Stole  and  Leaked  a  Megatrove  of  Police  Documents 

-  www.zdnet.com:  BlueLeaks:  Data  from  200  US  police  departments  &  fusion  centers  published  online 

-  www.cyberscoop.com:  'Distributed  Denial  of  Secrets'  publishes  'Blue  Leaks,'  a  trove  of  law  enforcement  records 

-  www.vice.com:  ‘BlueLeaks’:  Group  Releases  270GB  of  Sensitive  Police  Documents 


Data  Stolen  from  US  Law  Enforcement  Databases 


From: 

To: 


Arunas  Buntinas  (Sheriff)  <Arunas. Buntinas2@cookcountyil.gov> 

Leo  Schmitz  (Sheriff)  <Leo.Schmitz@cookcountyil.gov>,  Marlon  Parks  (Sheriff) 
<Marlon.Parks@cookcountyil.gov>,  Brian  White  (Sheriff) 


Sent: 

Received: 


<  B ria  n .  Wh  ite@coo kco u  nty i  I  .go v> 
June  23,  2020  5:49:35  PM  CDT 
June  23,  2020  5:49:37  PM  CDT 


Group  Posts  269  GB  of  Data  Stolen  from  US  Law  Enforcement  Databases 

(June  22,  2020) 

A  group  calling  itself  Distributed  Denial  of  Secrets  has  posted  269  gigabytes  of  police  data  online.  According  to  a 
memo  from  the  National  Fusion  Center  Association  obtained  by  Brian  Krebs,  the  data  were  taken  from  state  owned 
and  operated  law  enforcement  fusion  centers,  which  serve  to  coordinate  communications  between  state,  local, 
federal,  tribal,  territorial,  private  law  enforcement  partners.  The  memo  notes  that  “Preliminary  analysis  of  the  data 
contained  in  this  leak  suggests  that  Netsential,  a  web  services  company  used  by  multiple  fusion  centers,  law 
enforcement,  and  other  government  agencies  across  the  United  States,  was  the  source  of  the  compromise.” 

Read  more  in: 

-  krebsonsecurity.com:  ‘BlueLeaks’  Exposes  Files  from  Hundreds  of  Police  Departments 

-  arstechnica.com:  Millions  of  documents  from  >200  US  police  agencies  published  in  “BlueLeaks”  trove 

-  www.wired.com:  Hack  Brief:  Anonymous  Stole  and  Leaked  a  Megatrove  of  Police  Documents 

-  www.zdnet.com:  BlueLeaks:  Data  from  200  US  police  departments  &  fusion  centers  published  online 

-  www.cyberscoop.com:  'Distributed  Denial  of  Secrets'  publishes  'Blue  Leaks,'  a  trove  of  law  enforcement  records 

-  www.vice.com:  ‘BlueLeaks’:  Group  Releases  270GB  of  Sensitive  Police  Documents 

Sent  from  my  iPhone 


Re:  Data  Stolen  from  US  Law  Enforcement  Databases 


From: 

To: 

Cc: 


Arunas  Buntinas  (Sheriff)  <Arunas. Buntinas2@cookcountyil.gov> 

Marlon  Parks  (Sheriff)  <Marlon.Parks@cookcountyil.gov>,  Brian  White  (Sheriff) 


Leo.Schmitz@cookcountyil.gov 


Sent: 

Received: 


<  B ria  n .  Wh  ite@coo kco u  nty i  I  .go v> 
June  23,  2020  7:36:19  PM  CDT 
June  23,  2020  7:36:19  PM  CDT 


Did  they  get  any  of  our  info? 

Leo  P.  Schmitz 

Chief  of  Public  Safety 

Cook  County  Sheriffs  Department 


Sent  from  my  iPhone 

E-MAIL  CONFIDENTIALITY  NOTICE:  This  electronic  mail  message,  including  any  attachments,  is  for 
the  intended  recipient(s)  only.  This  e-mail  and  any  attachments  might  contain  information  that  is 
confidential,  legally  privileged,  contains  law  enforcement  database  information,  or  otherwise  protected  or 
exempt  from  disclosure  under  applicable  law.  If  you  are  not  a  named  recipient,  or  if  you  are  named  but 
believe  that  you  received  this  e-mail  in  error,  please  notify  the  sender  immediately  by  telephone  or  return  e- 
mail  and  promptly  delete  this  e-mail  and  any  attachments  and  copies  thereof  from  your  system.  If  you  are 
not  the  intended  recipient  or  are  otherwise  not  authorized  to  further  disclose  this  message  and  its  contents, 
please  be  aware  that  any  copying,  distribution,  dissemination,  disclosure  or  other  use  of  this  e-mail  and  any 
attachments  is  unauthorized  and  prohibited.  Your  receipt  of  this  message  is  not  intended  to  waive  any 
applicable  privilege  or  claim  of  confidentiality,  and  any  prohibited  or  unauthorized  disclosure  is  not  binding 
on  the  sender  or  the  Cook  County  Sheriffs  Office.  Thank  you  for  your  cooperation. 

On  Jun  23,  2020,  at  5:49  PM,  Arunas  Buntinas  (Sheriff) 

<Amnas.Buntinas2@cookcountyil.gov>  wrote: 


Group  Posts  269  GB  of  Data  Stolen  from  US  Law  Enforcement 
Databases 

(June  22,  2020) 

A  group  calling  itself  Distributed  Denial  of  Secrets  has  posted  269  gigabytes  of  police  data  online. 
According  to  a  memo  from  the  National  Fusion  Center  Association  obtained  by  Brian  Krebs,  the  data 
were  taken  from  state  owned  and  operated  law  enforcement  fusion  centers,  which  serve  to  coordinate 
communications  between  state,  local,  federal,  tribal,  territorial,  private  law  enforcement  partners.  The 
memo  notes  that  “Preliminary  analysis  of  the  data  contained  in  this  leak  suggests  that  Netsential,  a  web 
services  company  used  by  multiple  fusion  centers,  law  enforcement,  and  other  government  agencies 
across  the  United  States,  was  the  source  of  the  compromise.” 

Read  more  in: 

-  krebsonsecurity.com:  ‘BlueLeaks’  Exposes  Files  from  Hundreds  of  Police  Departments 

-  arstechnica.com:  Millions  of  documents  from  >200  US  police  agencies  published  in  “BlueLeaks”  trove 

-  www.wired.com:  Hack  Brief:  Anonymous  Stole  and  Leaked  a  Megatrove  of  Police  Documents 
www.zdnet.com:  BlueLeaks:  Data  from  200  US  police  departments  &  fusion  centers  published  online 

-  www.cyberscoop.com :  'Distributed  Denial  of  Secrets'  publishes  'Blue  Leaks,'  a  trove  of  law 
enforcement  records 

-  www.vice.com:  ‘BlueLeaks’:  Group  Releases  270GB  of  Sensitive  Police  Documents 


Sent  from  my  iPhone 


Re:  Data  Stolen  from  US  Law  Enforcement  Databases 


From:  Leo  Schmitz  (Sheriff)  </0=EXCHANGELABS/OU=EXCHANGE  ADMINISTRATIVE 

GROUP 

(FYDIBOHF23SPDLT)/CN=RECIPIENTS/CN=D9CD12213A744B67BF85F400559CE4A 
7-LEO  SCHMITZ> 

To:  Arunas  Buntinas  (Sheriff)  <Arunas. Buntinas2@cookcountyil.gov> 

Cc:  Marlon  Parks  (Sheriff)  <Marlon.Parks@cookcountyil.gov>,  Brian  White  (Sheriff) 

<  B  ria  n .  Wh  ite@coo  kcountyil.gov> 

Sent:  June  23,  2020  7:36:19  PM  CDT 

Received:  June  23,  2020  7:36:20  PM  CDT 

Did  they  get  any  of  our  info? 

Leo  P.  Schmitz 

Chief  of  Public  Safety 

Cook  County  Sheriffs  Department 


Sent  from  my  iPhone 

E-MAIL  CONFIDENTIALITY  NOTICE:  This  electronic  mail  message,  including  any  attachments,  is  for 
the  intended  recipient(s)  only.  This  e-mail  and  any  attachments  might  contain  information  that  is 
confidential,  legally  privileged,  contains  law  enforcement  database  information,  or  otherwise  protected  or 
exempt  from  disclosure  under  applicable  law.  If  you  are  not  a  named  recipient,  or  if  you  are  named  but 
believe  that  you  received  this  e-mail  in  error,  please  notify  the  sender  immediately  by  telephone  or  return  e- 
mail  and  promptly  delete  this  e-mail  and  any  attachments  and  copies  thereof  from  your  system.  If  you  are 
not  the  intended  recipient  or  are  otherwise  not  authorized  to  further  disclose  this  message  and  its  contents, 
please  be  aware  that  any  copying,  distribution,  dissemination,  disclosure  or  other  use  of  this  e-mail  and  any 
attachments  is  unauthorized  and  prohibited.  Your  receipt  of  this  message  is  not  intended  to  waive  any 
applicable  privilege  or  claim  of  confidentiality,  and  any  prohibited  or  unauthorized  disclosure  is  not  binding 
on  the  sender  or  the  Cook  County  Sheriffs  Office.  Thank  you  for  your  cooperation. 


On  Jun  23,  2020,  at  5:49  PM,  Arunas  Buntinas  (Sheriff) 
<  Arunas  .Buntinas2@cookcountyil.  go  v>  wrote : 


Group  Posts  269  GB  of  Data  Stolen  from  US  Law  Enforcement 
Databases 

(June  22,  2020) 

A  group  calling  itself  Distributed  Denial  of  Secrets  has  posted  269  gigabytes  of  police  data  online. 
According  to  a  memo  from  the  National  Fusion  Center  Association  obtained  by  Brian  Krebs,  the  data 
were  taken  from  state  owned  and  operated  law  enforcement  fusion  centers,  which  serve  to  coordinate 
communications  between  state,  local,  federal,  tribal,  territorial,  private  law  enforcement  partners.  The 
memo  notes  that  “Preliminary  analysis  of  the  data  contained  in  this  leak  suggests  that  Netsentiai,  a  web 
services  company  used  by  multiple  fusion  centers,  law  enforcement,  and  other  government  agencies 
across  the  United  States,  was  the  source  of  the  compromise.” 

Read  more  in: 

-  krebsonsecuritv.com:  ‘BlueLeaks’  Exposes  Files  from  Hundreds  of  Police  Departments 

-  arstechnica.com:  Millions  of  documents  from  >200  US  police  agencies  published  in  “BlueLeaks”  trove 

-  www.wired.com:  Hack  Brief:  Anonymous  Stole  and  Leaked  a  Megatrove  of  Police  Documents 

-  www.zdnet.com:  BlueLeaks:  Data  from  200  US  police  departments  &  fusion  centers  published  online 

-  www.cyberscoop.com :  'Distributed  Denial  of  Secrets'  publishes  'Blue  Leaks,'  a  trove  of  law 


enforcement  records 

-  www.vice.com:  ‘BlueLeaks’:  Group  Releases  270GB  of  Sensitive  Police  Documents 
Sent  from  my  iPhone 


Fwd:  Data  Stolen  from  US  Law  Enforcement  Databases 


From:  Leo.Schmitz@cookcountyil.gov 

To:  Amar  Patel  <Amar.Patel@cookcountyil.gov>,  Amar  Patel  (Sheriff) 

<Amar.Patel@cookcountyil.gov> 

Sent:  June  23,  2020  7:37:01  PM  CDT 

Received:  June  23,  2020  7:37:02  PM  CDT 

This  affect  us  in  any  way? 

Leo  P.  Schmitz 

Chief  of  Public  Safety 

Cook  County  Sheriffs  Department 


Sent  from  my  iPhone 

E-MAIL  CONFIDENTIALITY  NOTICE:  This  electronic  mail  message,  including  any  attachments,  is  for 
the  intended  recipient! s)  only.  This  e-mail  and  any  attachments  might  contain  information  that  is 
confidential,  legally  privileged,  contains  law  enforcement  database  information,  or  otherwise  protected  or 
exempt  from  disclosure  under  applicable  law.  If  you  are  not  a  named  recipient,  or  if  you  are  named  but 
believe  that  you  received  this  e-mail  in  error,  please  notify  the  sender  immediately  by  telephone  or  return  e- 
mail  and  promptly  delete  this  e-mail  and  any  attachments  and  copies  thereof  from  your  system.  If  you  are 
not  the  intended  recipient  or  are  otherwise  not  authorized  to  further  disclose  this  message  and  its  contents, 
please  be  aware  that  any  copying,  distribution,  dissemination,  disclosure  or  other  use  of  this  e-mail  and  any 
attachments  is  unauthorized  and  prohibited.  Your  receipt  of  this  message  is  not  intended  to  waive  any 
applicable  privilege  or  claim  of  confidentiality,  and  any  prohibited  or  unauthorized  disclosure  is  not  binding 
on  the  sender  or  the  Cook  County  Sheriffs  Office.  Thank  you  for  your  cooperation. 

Begin  forwarded  message: 


From:  "Leo  Schmitz  (Sheriff)"  <Leo.Schmitz@cookcountyil.gov> 

Date:  June  23,  2020  at  7:36:20  PM  CDT 

To:  "Aranas  Buntinas  (Sheriff)"  <Aranas.Buntinas2@cookcountyil.gov> 

Cc:  "Marlon  Parks  (Sheriff)"  <Marlon.Parks@cookcountyil.gov>,  "Brian  White  (Sheriff)" 
<Brian.White@cookcountyil.gov> 

Subject:  Re:  Data  Stolen  from  US  Law  Enforcement  Databases 


Did  they  get  any  of  our  info? 

Leo  P.  Schmitz 

Chief  of  Public  Safety 

Cook  County  Sheriffs  Department 


Sent  from  my  iPhone 

E-MAIL  CONFIDENTIALITY  NOTICE:  This  electronic  mail  message,  including  any 
attachments,  is  for  the  intended  recipient(s)  only.  This  e-mail  and  any  attachments  might 
contain  information  that  is  confidential,  legally  privileged,  contains  law  enforcement  database 
information,  or  otherwise  protected  or  exempt  from  disclosure  under  applicable  law.  If  you  are 
not  a  named  recipient,  or  if  you  are  named  but  believe  that  you  received  this  e-mail  in  error, 
please  notify  the  sender  immediately  by  telephone  or  return  e-mail  and  promptly  delete  this  e- 


mail  and  any  attachments  and  copies  thereof  from  your  system.  If  you  are  not  the  intended 
recipient  or  are  otherwise  not  authorized  to  further  disclose  this  message  and  its  contents,  please 
be  aware  that  any  copying,  distribution,  dissemination,  disclosure  or  other  use  of  this  e-mail  and 
any  attachments  is  unauthorized  and  prohibited.  Your  receipt  of  this  message  is  not  intended  to 
waive  any  applicable  privilege  or  claim  of  confidentiality,  and  any  prohibited  or  unauthorized 
disclosure  is  not  binding  on  the  sender  or  the  Cook  County  Sheriffs  Office.  Thank  you  for  your 
cooperation. 


On  Jun  23,  2020,  at  5:49  PM,  Arunas  Buntinas  (Sheriff) 
<Arunas.Buntinas2@cookcountyil.gov>  wrote: 


Group  Posts  269  GB  of  Data  Stolen  from  US  Law  Enforcement 
Databases 

(June  22,  2020) 

A  group  calling  itself  Distributed  Denial  of  Secrets  has  posted  269  gigabytes  of  police  data 
online.  According  to  a  memo  from  the  National  Fusion  Center  Association  obtained  by 
Brian  Krebs,  the  data  were  taken  from  state  owned  and  operated  law  enforcement  fusion 
centers,  which  serve  to  coordinate  communications  between  state,  local,  federal,  tribal, 
territorial,  private  law  enforcement  partners.  The  memo  notes  that  “Preliminary  analysis  of 
the  data  contained  in  this  leak  suggests  that  Netsential,  a  web  services  company  used  by 
multiple  fusion  centers,  law  enforcement,  and  other  government  agencies  across  the 
United  States,  was  the  source  of  the  compromise.” 

Read  more  in: 

-  krebsonsecuritv.com:  ‘BlueLeaks’  Exposes  Files  from  Hundreds  of  Police  Departments 

-  arstechnica.com:  Millions  of  documents  from  >200  US  police  agencies  published  in 
“BlueLeaks”  trove 

-  www.wired.com:  Hack  Brief:  Anonymous  Stole  and  Leaked  a  Megatrove  of  Police 
Documents 

-  www.zdnet.com:  BlueLeaks:  Data  from  200  US  police  departments  &  fusion  centers 
published  online 

-  www.cyberscoop.com:  'Distributed  Denial  of  Secrets'  publishes  'Blue  Leaks,'  a  trove  of 
law  enforcement  records 

-  www.vice.com:  ‘BlueLeaks’:  Group  Releases  270GB  of  Sensitive  Police  Documents 


Sent  from  my  iPhone 


Fwd:  Data  Stolen  from  US  Law  Enforcement  Databases 


From:  Leo  Schmitz  (Sheriff)  <Leo.Schmitz@cookcountyil.gov> 

To:  Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov> 

Sent:  June  23,  2020  7:37:02  PM  CDT 

Received:  June  23,  2020  7:37:03  PM  CDT 

This  affect  us  in  any  way? 

Leo  P.  Schmitz 

Chief  of  Public  Safety 

Cook  County  Sheriffs  Department 


Sent  from  my  iPhone 

E-MAIL  CONFIDENTIALITY  NOTICE:  This  electronic  mail  message,  including  any  attachments,  is  for 
the  intended  recipient(s)  only.  This  e-mail  and  any  attachments  might  contain  information  that  is 
confidential,  legally  privileged,  contains  law  enforcement  database  information,  or  otherwise  protected  or 
exempt  from  disclosure  under  applicable  law.  If  you  are  not  a  named  recipient,  or  if  you  are  named  but 
believe  that  you  received  this  e-mail  in  error,  please  notify  the  sender  immediately  by  telephone  or  return  e- 
mail  and  promptly  delete  this  e-mail  and  any  attachments  and  copies  thereof  from  your  system.  If  you  are 
not  the  intended  recipient  or  are  otherwise  not  authorized  to  further  disclose  this  message  and  its  contents, 
please  be  aware  that  any  copying,  distribution,  dissemination,  disclosure  or  other  use  of  this  e-mail  and  any 
attachments  is  unauthorized  and  prohibited.  Your  receipt  of  this  message  is  not  intended  to  waive  any 
applicable  privilege  or  claim  of  confidentiality,  and  any  prohibited  or  unauthorized  disclosure  is  not  binding 
on  the  sender  or  the  Cook  County  Sheriffs  Office.  Thank  you  for  your  cooperation. 

Begin  forwarded  message: 


From:  "Leo  Schmitz  (Sheriff)"  <Leo.Schmitz@cookcountyil.gov> 

Date:  June  23,  2020  at  7:36:20  PM  CDT 

To:  "Arunas  Buntinas  (Sheriff)"  <Arunas.Buntinas2@cookcountyil.gov> 

Cc:  "Marlon  Parks  (Sheriff)"  <Marlon.Parks@cookcountyil.gov>,  "Brian  White  (Sheriff)" 
<Brian.White@cookcountyil.gov> 

Subject:  Re:  Data  Stolen  from  US  Law  Enforcement  Databases 


Did  they  get  any  of  our  info? 

Leo  P.  Schmitz 

Chief  of  Public  Safety 

Cook  County  Sheriffs  Department 


Sent  from  my  iPhone 

E-MAIL  CONFIDENTIALITY  NOTICE:  This  electronic  mail  message,  including  any 
attachments,  is  for  the  intended  recipient(s)  only.  This  e-mail  and  any  attachments  might 
contain  information  that  is  confidential,  legally  privileged,  contains  law  enforcement  database 
information,  or  otherwise  protected  or  exempt  from  disclosure  under  applicable  law.  If  you  are 
not  a  named  recipient,  or  if  you  are  named  but  believe  that  you  received  this  e-mail  in  error, 
please  notify  the  sender  immediately  by  telephone  or  return  e-mail  and  promptly  delete  this  e- 
mail  and  any  attachments  and  copies  thereof  from  your  system.  If  you  are  not  the  intended 


recipient  or  are  otherwise  not  authorized  to  further  disclose  this  message  and  its  contents,  please 
be  aware  that  any  copying,  distribution,  dissemination,  disclosure  or  other  use  of  this  e-mail  and 
any  attachments  is  unauthorized  and  prohibited.  Your  receipt  of  this  message  is  not  intended  to 
waive  any  applicable  privilege  or  claim  of  confidentiality,  and  any  prohibited  or  unauthorized 
disclosure  is  not  binding  on  the  sender  or  the  Cook  County  Sheriffs  Office.  Thank  you  for  your 
cooperation. 


On  Jun  23,  2020,  at  5:49  PM,  Arunas  Buntinas  (Sheriff) 
<Arunas.Buntinas2@cookcountyil.gov>  wrote: 


Group  Posts  269  GB  of  Data  Stolen  from  US  Law  Enforcement 
Databases 

(June  22,  2020) 

A  group  calling  itself  Distributed  Denial  of  Secrets  has  posted  269  gigabytes  of  police  data 
online.  According  to  a  memo  from  the  National  Fusion  Center  Association  obtained  by 
Brian  Krebs,  the  data  were  taken  from  state  owned  and  operated  law  enforcement  fusion 
centers,  which  serve  to  coordinate  communications  between  state,  local,  federal,  tribal, 
territorial,  private  law  enforcement  partners.  The  memo  notes  that  “Preliminary  analysis  of 
the  data  contained  in  this  leak  suggests  that  Netsential,  a  web  services  company  used  by 
multiple  fusion  centers,  law  enforcement,  and  other  government  agencies  across  the 
United  States,  was  the  source  of  the  compromise.” 

Read  more  in: 

-  krebsonsecurity.com:  ‘BlueLeaks’  Exposes  Files  from  Hundreds  of  Police  Departments 

-  arstechnica.com:  Millions  of  documents  from  >200  US  police  agencies  published  in 
“BlueLeaks”  trove 

-  www.wired.com:  Hack  Brief:  Anonymous  Stole  and  Leaked  a  Megatrove  of  Police 
Documents 

-  www.zdnet.com:  BlueLeaks:  Data  from  200  US  police  departments  &  fusion  centers 
published  online 

-  www.cyberscoop.com:  'Distributed  Denial  of  Secrets'  publishes  'Blue  Leaks,'  a  trove  of 
law  enforcement  records 

-  www.vice.com:  ‘BlueLeaks’:  Group  Releases  270GB  of  Sensitive  Police  Documents 


Sent  from  my  iPhone 


Fwd:  Data  Stolen  from  US  Law  Enforcement  Databases 


From:  Leo  Schmitz  (Sheriff)  </0=EXCHANGELABS/OU=EXCHANGE  ADMINISTRATIVE 

GROUP 

(FYDIBOHF23SPDLT)/CN=RECIPIENTS/CN=D9CD12213A744B67BF85F400559CE4A 
7-LEO  SCHMITZ> 

To:  Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov> 

Sent:  June  23,  2020  7:37:02  PM  CDT 

Received:  June  23,  2020  7:37:03  PM  CDT 

This  affect  us  in  any  way? 

Leo  P.  Schmitz 

Chief  of  Public  Safety 

Cook  County  Sheriffs  Department 


Sent  from  my  iPhone 

E-MAIL  CONFIDENTIALITY  NOTICE:  This  electronic  mail  message,  including  any  attachments,  is  for 
the  intended  recipient! s)  only.  This  e-mail  and  any  attachments  might  contain  information  that  is 
confidential,  legally  privileged,  contains  law  enforcement  database  information,  or  otherwise  protected  or 
exempt  from  disclosure  under  applicable  law.  If  you  are  not  a  named  recipient,  or  if  you  are  named  but 
believe  that  you  received  this  e-mail  in  error,  please  notify  the  sender  immediately  by  telephone  or  return  e- 
mail  and  promptly  delete  this  e-mail  and  any  attachments  and  copies  thereof  from  your  system.  If  you  are 
not  the  intended  recipient  or  are  otherwise  not  authorized  to  further  disclose  this  message  and  its  contents, 
please  be  aware  that  any  copying,  distribution,  dissemination,  disclosure  or  other  use  of  this  e-mail  and  any 
attachments  is  unauthorized  and  prohibited.  Your  receipt  of  this  message  is  not  intended  to  waive  any 
applicable  privilege  or  claim  of  confidentiality,  and  any  prohibited  or  unauthorized  disclosure  is  not  binding 
on  the  sender  or  the  Cook  County  Sheriffs  Office.  Thank  you  for  your  cooperation. 

Begin  forwarded  message: 


From:  "Leo  Schmitz  (Sheriff)"  <Leo.Schmitz@cookcountyil.gov> 

Date:  June  23,  2020  at  7:36:20  PM  CDT 

To:  "Arunas  Buntinas  (Sheriff)"  <Arunas.Buntinas2@cookcountyil.gov> 

Cc:  "Marlon  Parks  (Sheriff)"  <Marlon.Parks@cookcountyil.gov>,  "Brian  White  (Sheriff)" 
<Brian.White@cookcountyil.gov> 

Subject:  Re:  Data  Stolen  from  US  Law  Enforcement  Databases 


Did  they  get  any  of  our  info? 

Leo  P.  Schmitz 

Chief  of  Public  Safety 

Cook  County  Sheriffs  Department 


Sent  from  my  iPhone 

E-MAIL  CONFIDENTIALITY  NOTICE:  This  electronic  mail  message,  including  any 
attachments,  is  for  the  intended  recipient(s)  only.  This  e-mail  and  any  attachments  might 
contain  information  that  is  confidential,  legally  privileged,  contains  law  enforcement  database 
information,  or  otherwise  protected  or  exempt  from  disclosure  under  applicable  law.  If  you  are 
not  a  named  recipient,  or  if  you  are  named  but  believe  that  you  received  this  e-mail  in  error, 


please  notify  the  sender  immediately  by  telephone  or  return  e-mail  and  promptly  delete  this  e- 
mail  and  any  attachments  and  copies  thereof  from  your  system.  If  you  are  not  the  intended 
recipient  or  are  otherwise  not  authorized  to  further  disclose  this  message  and  its  contents,  please 
be  aware  that  any  copying,  distribution,  dissemination,  disclosure  or  other  use  of  this  e-mail  and 
any  attachments  is  unauthorized  and  prohibited.  Your  receipt  of  this  message  is  not  intended  to 
waive  any  applicable  privilege  or  claim  of  confidentiality,  and  any  prohibited  or  unauthorized 
disclosure  is  not  binding  on  the  sender  or  the  Cook  County  Sheriffs  Office.  Thank  you  for  your 
cooperation. 


On  Jun  23,  2020,  at  5:49  PM,  Arunas  Buntinas  (Sheriff) 
<Arunas.Buntinas2@cookcountyil.gov>  wrote: 


Group  Posts  269  GB  of  Data  Stolen  from  US  Law  Enforcement 
Databases 

(June  22,  2020) 

A  group  calling  itself  Distributed  Denial  of  Secrets  has  posted  269  gigabytes  of  police  data 
online.  According  to  a  memo  from  the  National  Fusion  Center  Association  obtained  by 
Brian  Krebs,  the  data  were  taken  from  state  owned  and  operated  law  enforcement  fusion 
centers,  which  serve  to  coordinate  communications  between  state,  local,  federal,  tribal, 
territorial,  private  law  enforcement  partners.  The  memo  notes  that  “Preliminary  analysis  of 
the  data  contained  in  this  leak  suggests  that  Netsential,  a  web  services  company  used  by 
multiple  fusion  centers,  law  enforcement,  and  other  government  agencies  across  the 
United  States,  was  the  source  of  the  compromise.” 

Read  more  in: 

-  krebsonsecuritv.com:  ‘BlueLeaks’  Exposes  Files  from  Hundreds  of  Police  Departments 

-  arstechnica.com:  Millions  of  documents  from  >200  US  police  agencies  published  in 
“BlueLeaks”  trove 

-  www.wired.com:  Hack  Brief:  Anonymous  Stole  and  Leaked  a  Megatrove  of  Police 
Documents 

-  www.zdnet.com:  BlueLeaks:  Data  from  200  US  police  departments  &  fusion  centers 
published  online 

www.cyberscoop.com:  'Distributed  Denial  of  Secrets'  publishes  'Blue  Leaks,'  a  trove  of 
law  enforcement  records 

-  www.vice.com:  ‘BlueLeaks’:  Group  Releases  270GB  of  Sensitive  Police  Documents 


Sent  from  my  iPhone 


Fwd:  Data  Leak 


From:  Leo  Schmitz  (Sheriff)  <Leo. Schmitz@cookcountyil.gov> 

To:  Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov>,  Bradley  Curry  (Sheriff) 

<Bradley.Curry@cookcountyil.gov>,  Marlon  Parks  (Sheriff) 
<Marlon.Parks@cookcountyil.gov>,  Brian  White  (Sheriff) 
<Brian.White@cookcountyil.gov>,  Arunas  Buntinas  (Sheriff) 

<Arunas. Buntinas2@cookcountyil.gov> 

Sent:  June  23,  2020  7:52:35  PM  CDT 

Received:  June  23,  2020  7:52:36  PM  CDT 

FYI 

Leo  P.  Schmitz 

Chief  of  Public  Safety 

Cook  County  Sheriffs  Department 


Sent  from  my  iPhone 

E-MAIL  CONFIDENTIALITY  NOTICE:  This  electronic  mail  message,  including  any  attachments,  is  for 
the  intended  recipient(s)  only.  This  e-mail  and  any  attachments  might  contain  information  that  is 
confidential,  legally  privileged,  contains  law  enforcement  database  information,  or  otherwise  protected  or 
exempt  from  disclosure  under  applicable  law.  If  you  are  not  a  named  recipient,  or  if  you  are  named  but 
believe  that  you  received  this  e-mail  in  error,  please  notify  the  sender  immediately  by  telephone  or  return  e- 
mail  and  promptly  delete  this  e-mail  and  any  attachments  and  copies  thereof  from  your  system.  If  you  are 
not  the  intended  recipient  or  are  otherwise  not  authorized  to  further  disclose  this  message  and  its  contents, 
please  be  aware  that  any  copying,  distribution,  dissemination,  disclosure  or  other  use  of  this  e-mail  and  any 
attachments  is  unauthorized  and  prohibited.  Your  receipt  of  this  message  is  not  intended  to  waive  any 
applicable  privilege  or  claim  of  confidentiality,  and  any  prohibited  or  unauthorized  disclosure  is  not  binding 
on  the  sender  or  the  Cook  County  Sheriffs  Office.  Thank  you  for  your  cooperation. 

Begin  forwarded  message: 


From:  Nick  Roti  <nroti@chicago-hidta.org> 

Date:  June  23,  2020  at  7:45:28  PM  CDT 

To:  "Leo  Schmitz  (Sheriff)"  <Leo. Schmitz@cookcountyil.gov> 

Subject:  Fwd:  Data  Leak 


External  Message  Disclaimer 


This  message  originated  from  an  external  source.  Please  use  proper  judgment  and 
caution  when  opening  attachments,  clicking  links,  or  responding  to  this  email. 


FYI 

Nicholas  J.  Roti 
Executive  Director 
Chicago  HIDTA 
312.448.5666  Office 
312.617.7237  Cell 
nroti@chicago-hidta.org 


Begin  forwarded  message: 


From:  "Leopold,  Daniel  J"  <Daniel.J.Leopold@ice.dhs.gov> 

Date:  June  23,  2020  at  6:40:39  PM  CDT 
To:  Brian  Wolfe  <mbwolfe@fbi.gov>,  Leo  Panepinto 
<Leo.Panepinto@chicagopolice.org>,  "Quinn,  Patrick" 
<patrick.quinn@chicagopolice.org>,  Aaron  Kustermann 

<aaron_kustermann@isp.state.il.us>,  Darrell  Aders  <darrell_aders@isp. state. il.us>, 
"Workman,  Byron"  <Byron.Workman@illinois.gov>,  Alison  Jacobs 
<alison.l.jacobs2.mil@mail.mil>,  James  G  Probst  <james.g.probst.mil@mail.mil>, 
"dale.k.kirkendoll.mil@mail.mil"  <dale.k.kirkendoll.mil@mail.mil>,  Steven  Artino 
<steven.t.artino@cbp.dhs.gov>,  "robert.w.harris@dhs.gov" 
<robert.w.harris@dhs.gov>,  Christian  Hoffman 

<Christian.M.Hoffman@usdoj.gov>,  Jim  Crotty  <james.m.crotty@usdoj.gov>, 
Patrick  O'Dea  <patrick.j.o'dea@usdoj.gov>,  Nick  Roti  <nroti@chicago-hidta.org>, 
Jessica  Ipema  <Jessica.m.ipema@usdoj.gov>,  "MARK.DELIA@ILLINOIS.GOV" 
<MARK.DELIA@ILLINOIS.GOV>,  Robert  Graves  <rmgraves@fbi.gov>, 
"Womiak,  Adam  T.  (CG)  (FBI)"  <atworniak@fbi.gov>,  "Krumrei,  Erich  W.  (CG) 
(FBI)"  <ewkrumrei@fbi.gov>,  Jeffrey  Rauch  <jdrauch@fbi.gov>,  "Chellberg, 
Samantha  (CG)  (FBI)"  <schellberg@fbi.gov>,  "Justiniano,  Robert  (CG)  (FBI)" 
<rjustiniano@fbi.gov>,  "JVButhom@uspis.gov"  <JVButhom@uspis.gov> 

Cc:  Daniel  Feopold  <daniel.j.leopold@ice.dhs.gov> 

Subject:  Data  Leak 


All,  see  below  link  related  to  a  massive  data  breach  exposing  24  years'  worth  of 
documents,  PII,  RFIs,  etc.  from  over  200  federal,  state,  and  local  police 
departments.  Apparently,  there  is  270  gigs  of  data. 

https://krebsonsecurity.com/2020/06/blueleaks-exposes-files-ffom-hundreds-of- 

police-departments/ 

Thanks, 

Dan 

Daniel  J.  Feopold  |  Chief  Intelligence  Officer 
DHS  -  ICE  |  Homeland  Security  Investigations  |  SAC  Chicago 
One  Tower  Lane,  Suite  1600  |  Oakbrook  Terrace,  Illinois  60181 
(630)  441-8343  (c)(  |  (630)  574-4121  |  daniel.j.leopold@ice.dhs.gov 
Illinoisl  Indiana  (Wisconsin 

WARNING:  This  email  and  any  attachments  are  UNCLAS SIFIED//F OR 
OFFICIAL  USE  ONLY  (U//FOUO).  It  contains  information  that  may  be  exempt 
from  public  release  under  the  Freedom  of  Information  Act  (5  U.S.C.  552).  It  is  to 
be  controlled,  stored,  handled,  transmitted,  distributed,  and  disposed  of  in 
accordance  with  DHS  policy  relating  to  FOUO  information  and  is  not  to  be 
released  to  the  public  or  other  personnel  who  do  not  have  a  valid  "need-to-know" 
without  prior  approval  of  an  authorized  DHS  official.  No  portion  of  this  email 
should  be  furnished  to  the  media,  either  in  written  or  verbal  form.  If  you  are  not  an 
intended  recipient  or  believe  you  have  received  this  communication  in  error,  please 
do  not  print,  copy,  retransmit,  disseminate,  or  otherwise  use  this  information. 


Please  inform  the  sender  that  you  received  this  message  in  error  and  delete  the 
message  from  your  system. 


Fwd:  Data  Leak 


From:  Leo  Schmitz  (Sheriff)  </0=EXCHANGELABS/OU=EXCHANGE  ADMINISTRATIVE 

GROUP 

(FYDIBOHF23SPDLT)/CN=RECIPIENTS/CN=D9CD12213A744B67BF85F400559CE4A 
7-LEO  SCHMITZ> 

To:  Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov>,  Bradley  Curry  (Sheriff) 

<Bradley.Curry@cookcountyil.gov>,  Marlon  Parks  (Sheriff) 
<Marlon.Parks@cookcountyil.gov>,  Brian  White  (Sheriff) 
<Brian.White@cookcountyil.gov>,  Arunas  Buntinas  (Sheriff) 

<Arunas. Buntinas2@cookcountyil.gov> 

Sent:  June  23,  2020  7:52:35  PM  CDT 

Received:  June  23,  2020  7:52:36  PM  CDT 

FYI 

Leo  P.  Schmitz 

Chief  of  Public  Safety 

Cook  County  Sheriffs  Department 


Sent  from  my  iPhone 

E-MAIL  CONFIDENTIALITY  NOTICE:  This  electronic  mail  message,  including  any  attachments,  is  for 
the  intended  recipient(s)  only.  This  e-mail  and  any  attachments  might  contain  information  that  is 
confidential,  legally  privileged,  contains  law  enforcement  database  information,  or  otherwise  protected  or 
exempt  from  disclosure  under  applicable  law.  If  you  are  not  a  named  recipient,  or  if  you  are  named  but 
believe  that  you  received  this  e-mail  in  error,  please  notify  the  sender  immediately  by  telephone  or  return  e- 
mail  and  promptly  delete  this  e-mail  and  any  attachments  and  copies  thereof  from  your  system.  If  you  are 
not  the  intended  recipient  or  are  otherwise  not  authorized  to  further  disclose  this  message  and  its  contents, 
please  be  aware  that  any  copying,  distribution,  dissemination,  disclosure  or  other  use  of  this  e-mail  and  any 
attachments  is  unauthorized  and  prohibited.  Your  receipt  of  this  message  is  not  intended  to  waive  any 
applicable  privilege  or  claim  of  confidentiality,  and  any  prohibited  or  unauthorized  disclosure  is  not  binding 
on  the  sender  or  the  Cook  County  Sheriffs  Office.  Thank  you  for  your  cooperation. 

Begin  forwarded  message: 


From:  Nick  Roti  <nroti@chicago-hidta.org> 

Date:  June  23,  2020  at  7:45:28  PM  CDT 

To:  "Leo  Schmitz  (Sheriff)"  <Leo. Schmitz@cookcountyil.gov> 

Subject:  Fwd:  Data  Leak 


External  Message  Disclaimer 


This  message  originated  from  an  external  source.  Please  use  proper  judgment  and 


FYI 

Nicholas  J.  Roti 
Executive  Director 
Chicago  HIDTA 


312.448.5666  Office 
312.617.7237  Cell 
nroti@chicago-hidta.org 


Begin  forwarded  message: 


From:  "Leopold,  Daniel  J"  <Daniel.J.Leopold@ice.dhs.gov> 

Date:  June  23,  2020  at  6:40:39  PM  CDT 
To:  Brian  Wolfe  <mbwolfe@fbi.gov>,  Leo  Panepinto 
<Leo.Panepinto@chicagopolice.org>,  "Quinn,  Patrick" 
<patrick.quinn@chicagopolice.org>,  Aaron  Kustermann 

<aaron_kustermann@isp.state.il.us>,  Darrell  Aders  <darrell_aders@isp.state.il.us>, 
"Workman,  Byron"  <Byron.Workman@illinois.gov>,  Alison  Jacobs 
<alison.l.jacobs2.mil@mail.mil>,  James  G  Probst  <james.g.probst.mil@mail.mil>, 
"dale.k.kirkendoll.mil@mail.mil"  <dale.k.kirkendoll.mil@mail.mil>,  Steven  Artino 
<steven.t.artino@cbp.dhs.gov>,  "robert.w.harris@dhs.gov" 
<robert.w.harris@dhs.gov>,  Christian  Hoffman 

<Christian.M.Hoffman@usdoj.gov>,  Jim  Crotty  <james.m.crotty@usdoj.gov>, 
Patrick  O'Dea  <patrick.j.o'dea@usdoj.gov>,  Nick  Roti  <nroti@chicago-hidta.org>, 
Jessica  Ipema  <Jessica.m.ipema@usdoj.gov>,  "MARK.DELIA@ILLINOIS.GOV" 
<MARK.DELIA@ILLINOIS.GOV>,  Robert  Graves  <rmgraves@fbi.gov>, 
"Womiak,  Adam  T.  (CG)  (FBI)"  <atwomiak@fbi.gov>,  "Krumrei,  Erich  W.  (CG) 
(FBI)"  <ewkrumrei@fbi.gov>,  Jeffrey  Rauch  <jdrauch@fbi.gov>,  "Chellberg, 
Samantha  (CG)  (FBI)"  <schellberg@fbi.gov>,  "Justiniano,  Robert  (CG)  (FBI)" 
<rjustiniano@fbi.gov>,  "JVButhom@uspis.gov"  <JVButhom@uspis.gov> 

Cc:  Daniel  Feopold  <daniel.j.leopold@ice.dhs.gov> 

Subject:  Data  Leak 


All,  see  below  link  related  to  a  massive  data  breach  exposing  24  years'  worth  of 
documents,  PII,  RFIs,  etc.  from  over  200  federal,  state,  and  local  police 
departments.  Apparently,  there  is  270  gigs  of  data. 

https://krebsonsecurity.corn/2020/06/blueleaks-exposes-files-ffom-hundreds-of- 

police-departments/ 

Thanks, 

Dan 

Daniel  J.  Feopold  |  Chief  Intelligence  Officer 
DHS  -  ICE  |  Homeland  Security  Investigations  |  SAC  Chicago 
One  Tower  Fane,  Suite  1600  |  Oakbrook  Terrace,  Illinois  60181 
(630)  441-8343  (c)(  |  (630)  574-4121  |  daniel.j.leopold@ice.dhs.gov 
Illinoisl  Indiana  (Wisconsin 

WARNING:  This  email  and  any  attachments  are  UNCFASSIFIED//FOR 
OFFICIAF  USE  ONLY  (U//FOUO).  It  contains  information  that  may  be  exempt 
from  public  release  under  the  Freedom  of  Information  Act  (5  U.S.C.  552).  It  is  to 
be  controlled,  stored,  handled,  transmitted,  distributed,  and  disposed  of  in 
accordance  with  DHS  policy  relating  to  FOUO  information  and  is  not  to  be 
released  to  the  public  or  other  personnel  who  do  not  have  a  valid  "need-to-know" 
without  prior  approval  of  an  authorized  DHS  official.  No  portion  of  this  email 
should  be  furnished  to  the  media,  either  in  written  or  verbal  form.  If  you  are  not  an 


intended  recipient  or  believe  you  have  received  this  communication  in  error,  please 
do  not  print,  copy,  retransmit,  disseminate,  or  otherwise  use  this  information. 
Please  inform  the  sender  that  you  received  this  message  in  error  and  delete  the 
message  from  your  system. 


Re:  Data  Stolen  from  US  Law  Enforcement  Databases 


From: 

To: 

Sent: 

Received: 


Arunas.Buntinas2@cookcountyil.gov 

Leo  Schmitz  (Sheriff)  <Leo. Schmitz@cookcountyil.gov> 

June  23,  2020  8:26:04  PM  CDT 

June  23,  2020  8:26:05  PM  CDT 


Chief, 

Checking  on  it  now. 
Aranas 


On  Jun  23,  2020,  at  7:36  PM,  Leo  Schmitz  (Sheriff)  <Leo. Schmitz@cookcountyil.gov>  wrote: 

Did  they  get  any  of  our  info? 

Leo  P.  Schmitz 

Chief  of  Public  Safety 

Cook  County  Sheriffs  Department 


Sent  from  my  iPhone 

E-MAIL  CONFIDENTIALITY  NOTICE:  This  electronic  mail  message,  including  any 
attachments,  is  for  the  intended  recipient(s)  only.  This  e-mail  and  any  attachments  might 
contain  information  that  is  confidential,  legally  privileged,  contains  law  enforcement  database 
information,  or  otherwise  protected  or  exempt  from  disclosure  under  applicable  law.  If  you  are 
not  a  named  recipient,  or  if  you  are  named  but  believe  that  you  received  this  e-mail  in  error, 
please  notify  the  sender  immediately  by  telephone  or  return  e-mail  and  promptly  delete  this  e- 
mail  and  any  attachments  and  copies  thereof  from  your  system.  If  you  are  not  the  intended 
recipient  or  are  otherwise  not  authorized  to  further  disclose  this  message  and  its  contents,  please 
be  aware  that  any  copying,  distribution,  dissemination,  disclosure  or  other  use  of  this  e-mail  and 
any  attachments  is  unauthorized  and  prohibited.  Your  receipt  of  this  message  is  not  intended  to 
waive  any  applicable  privilege  or  claim  of  confidentiality,  and  any  prohibited  or  unauthorized 
disclosure  is  not  binding  on  the  sender  or  the  Cook  County  Sheriffs  Office.  Thank  you  for  your 
cooperation. 


On  Jun  23,  2020,  at  5:49  PM,  Aranas  Buntinas  (Sheriff) 
<Aranas.Buntinas2@cookcountyil.gov>  wrote: 


Group  Posts  269  GB  of  Data  Stolen  from  US  Law  Enforcement 
Databases 

(June  22,  2020) 

A  group  calling  itself  Distributed  Denial  of  Secrets  has  posted  269  gigabytes  of  police  data 
online.  According  to  a  memo  from  the  National  Fusion  Center  Association  obtained  by 
Brian  Krebs,  the  data  were  taken  from  state  owned  and  operated  law  enforcement  fusion 
centers,  which  serve  to  coordinate  communications  between  state,  local,  federal,  tribal, 
territorial,  private  law  enforcement  partners.  The  memo  notes  that  “Preliminary  analysis  of 
the  data  contained  in  this  leak  suggests  that  Netsential,  a  web  services  company  used  by 
multiple  fusion  centers,  law  enforcement,  and  other  government  agencies  across  the 


United  States,  was  the  source  of  the  compromise.” 


Read  more  in: 

-  krebsonsecurity.com:  ‘BlueLeaks’  Exposes  Files  from  Hundreds  of  Police  Departments 

-  arstechnica.com:  Millions  of  documents  from  >200  US  police  agencies  published  in 
“BlueLeaks”  trove 

-  www.wired.com:  Hack  Brief:  Anonymous  Stole  and  Leaked  a  Megatrove  of  Police 
Documents 

-  www.zdnet.com:  BlueLeaks:  Data  from  200  US  police  departments  &  fusion  centers 
published  online 

-  www.cyberscoop.com:  'Distributed  Denial  of  Secrets'  publishes  'Blue  Leaks,'  a  trove  of 
law  enforcement  records 

-  www.vice.com:  ‘BlueLeaks’:  Group  Releases  270GB  of  Sensitive  Police  Documents 
Sent  from  my  iPhone 


Re:  Data  Stolen  from  US  Law  Enforcement  Databases 


To: 

Sent: 

Received: 


Leo  Schmitz  (Sheriff) 

June  23,  2020  8:26:04  PM  CDT 
June  23,  2020  8:26:05  PM  CDT 


Re:  Data  Stolen  from  US  Law  Enforcement  Databases 


From: 

To: 

Sent: 

Received: 


Arunas  Buntinas  (Sheriff)  <Arunas. Buntinas2@cookcountyil.gov> 
Leo  Schmitz  (Sheriff)  <Leo. Schmitz@cookcountyil.gov> 

June  23,  2020  8:26:05  PM  CDT 
June  23,  2020  8:26:07  PM  CDT 


Chief, 

Checking  on  it  now. 
Aranas 


On  Jun  23,  2020,  at  7:36  PM,  Leo  Schmitz  (Sheriff)  <Leo. Schmitz@cookcountyil.gov>  wrote: 

Did  they  get  any  of  our  info? 

Leo  P.  Schmitz 

Chief  of  Public  Safety 

Cook  County  Sheriffs  Department 


Sent  from  my  iPhone 

E-MAIL  CONFIDENTIALITY  NOTICE:  This  electronic  mail  message,  including  any 
attachments,  is  for  the  intended  recipient(s)  only.  This  e-mail  and  any  attachments  might 
contain  information  that  is  confidential,  legally  privileged,  contains  law  enforcement  database 
information,  or  otherwise  protected  or  exempt  from  disclosure  under  applicable  law.  If  you  are 
not  a  named  recipient,  or  if  you  are  named  but  believe  that  you  received  this  e-mail  in  error, 
please  notify  the  sender  immediately  by  telephone  or  return  e-mail  and  promptly  delete  this  e- 
mail  and  any  attachments  and  copies  thereof  from  your  system.  If  you  are  not  the  intended 
recipient  or  are  otherwise  not  authorized  to  further  disclose  this  message  and  its  contents,  please 
be  aware  that  any  copying,  distribution,  dissemination,  disclosure  or  other  use  of  this  e-mail  and 
any  attachments  is  unauthorized  and  prohibited.  Your  receipt  of  this  message  is  not  intended  to 
waive  any  applicable  privilege  or  claim  of  confidentiality,  and  any  prohibited  or  unauthorized 
disclosure  is  not  binding  on  the  sender  or  the  Cook  County  Sheriffs  Office.  Thank  you  for  your 
cooperation. 


On  Jun  23,  2020,  at  5:49  PM,  Aranas  Buntinas  (Sheriff) 
<Aranas.Buntinas2@cookcountyil.gov>  wrote: 


Group  Posts  269  GB  of  Data  Stolen  from  US  Law  Enforcement 
Databases 

(June  22,  2020) 

A  group  calling  itself  Distributed  Denial  of  Secrets  has  posted  269  gigabytes  of  police  data 
online.  According  to  a  memo  from  the  National  Fusion  Center  Association  obtained  by 
Brian  Krebs,  the  data  were  taken  from  state  owned  and  operated  law  enforcement  fusion 
centers,  which  serve  to  coordinate  communications  between  state,  local,  federal,  tribal, 
territorial,  private  law  enforcement  partners.  The  memo  notes  that  “Preliminary  analysis  of 
the  data  contained  in  this  leak  suggests  that  Netsential,  a  web  services  company  used  by 
multiple  fusion  centers,  law  enforcement,  and  other  government  agencies  across  the 


United  States,  was  the  source  of  the  compromise.” 


Read  more  in: 

-  krebsonsecurity.com:  ‘BlueLeaks’  Exposes  Files  from  Hundreds  of  Police  Departments 

-  arstechnica.com:  Millions  of  documents  from  >200  US  police  agencies  published  in 
“BlueLeaks”  trove 

-  www.wired.com:  Hack  Brief:  Anonymous  Stole  and  Leaked  a  Megatrove  of  Police 
Documents 

-  www.zdnet.com:  BlueLeaks:  Data  from  200  US  police  departments  &  fusion  centers 
published  online 

-  www.cyberscoop.com:  'Distributed  Denial  of  Secrets'  publishes  'Blue  Leaks,'  a  trove  of 
law  enforcement  records 

-  www.vice.com:  ‘BlueLeaks’:  Group  Releases  270GB  of  Sensitive  Police  Documents 
Sent  from  my  iPhone 


Re:  Data  Stolen  from  US  Law  Enforcement  Databases 


From:  Arunas  Buntinas  (Sheriff)  </0=EXCHANGELABS/OU=EXCHANGE  ADMINISTRATIVE 

GROUP 

(FYDIBOHF23SPDLT)/CN=RECIPIENTS/CN=9E93BAED4821465CB7232E28F2421C4 
9-ARUNAS  BUNT> 

To:  Leo  Schmitz  (Sheriff)  <Leo.Schmitz@cookcountyil.gov> 

Sent:  June  23,  2020  8:26:05  PM  CDT 

Received:  June  23,  2020  8:26:06  PM  CDT 

Chief, 

Checking  on  it  now. 

Arunas 


On  Jun  23,  2020,  at  7:36  PM,  Leo  Schmitz  (Sheriff)  <Leo.Schmitz@cookcountyil.gov>  wrote: 


Did  they  get  any  of  our  info? 

Leo  P.  Schmitz 

Chief  of  Public  Safety 

Cook  County  Sheriffs  Department 


Sent  from  my  iPhone 

E-MAIL  CONFIDENTIALITY  NOTICE:  This  electronic  mail  message,  including  any 
attachments,  is  for  the  intended  recipient(s)  only.  This  e-mail  and  any  attachments  might 
contain  information  that  is  confidential,  legally  privileged,  contains  law  enforcement  database 
information,  or  otherwise  protected  or  exempt  from  disclosure  under  applicable  law.  If  you  are 
not  a  named  recipient,  or  if  you  are  named  but  believe  that  you  received  this  e-mail  in  error, 
please  notify  the  sender  immediately  by  telephone  or  return  e-mail  and  promptly  delete  this  e- 
mail  and  any  attachments  and  copies  thereof  from  your  system.  If  you  are  not  the  intended 
recipient  or  are  otherwise  not  authorized  to  further  disclose  this  message  and  its  contents,  please 
be  aware  that  any  copying,  distribution,  dissemination,  disclosure  or  other  use  of  this  e-mail  and 
any  attachments  is  unauthorized  and  prohibited.  Your  receipt  of  this  message  is  not  intended  to 
waive  any  applicable  privilege  or  claim  of  confidentiality,  and  any  prohibited  or  unauthorized 
disclosure  is  not  binding  on  the  sender  or  the  Cook  County  Sheriffs  Office.  Thank  you  for  your 
cooperation. 


On  Jun  23,  2020,  at  5:49  PM,  Arunas  Buntinas  (Sheriff) 
<Arunas.Buntinas2@cookcountyil.gov>  wrote: 


Group  Posts  269  GB  of  Data  Stolen  from  US  Law  Enforcement 
Databases 

(June  22,  2020) 

A  group  calling  itself  Distributed  Denial  of  Secrets  has  posted  269  gigabytes  of  police  data 
online.  According  to  a  memo  from  the  National  Fusion  Center  Association  obtained  by 
Brian  Krebs,  the  data  were  taken  from  state  owned  and  operated  law  enforcement  fusion 
centers,  which  serve  to  coordinate  communications  between  state,  local,  federal,  tribal, 
territorial,  private  law  enforcement  partners.  The  memo  notes  that  “Preliminary  analysis  of 


the  data  contained  in  this  leak  suggests  that  Netsential,  a  web  services  company  used  by 
multiple  fusion  centers,  law  enforcement,  and  other  government  agencies  across  the 
United  States,  was  the  source  of  the  compromise.” 

Read  more  in: 

-  krebsonsecurity.com:  ‘BlueLeaks’  Exposes  Files  from  Hundreds  of  Police  Departments 

-  arstechnica.com:  Millions  of  documents  from  >200  US  police  agencies  published  in 
“BlueLeaks”  trove 

-  www.wired.com:  Hack  Brief:  Anonymous  Stole  and  Leaked  a  Megatrove  of  Police 
Documents 

-  www.zdnet.com:  BlueLeaks:  Data  from  200  US  police  departments  &  fusion  centers 
published  online 

-  www.cyberscoop.com:  'Distributed  Denial  of  Secrets'  publishes  'Blue  Leaks,'  a  trove  of 
law  enforcement  records 

-  www.vice.com:  ‘BlueLeaks’:  Group  Releases  270GB  of  Sensitive  Police  Documents 
Sent  from  my  iPhone 


Re:  Data  Stolen  from  US  Law  Enforcement  Databases 


To: 

Sent: 

Received: 


Leo  Schmitz  (Sheriff),  Marlon  Parks  (Sheriff),  Brian  White  (Sheriff) 
June  23,  2020  8:26:05  PM  CDT 
June  23,  2020  8:26:06  PM  CDT 


Re:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


To:  Keith  Morrison  (Sheriff) 

Cc:  Adnan  Memon  (Sheriff),  Douglas  Maclean  (Sheriff) 

Sent:  June  23,  2020  8:30:56  PM  CDT 

Received:  June  23,  2020  8:30:56  PM  CDT 


Re:  Data  Leak 


To: 

Sent: 

Received: 


Leo  Schmitz  (Sheriff),  Bradley  Curry  (Sheriff),  Marlon  Parks  (Sheriff),  Brian  White 
(Sheriff),  Arunas  Buntinas  (Sheriff),  Tarry  Williams  (Sheriff),  Amar  Patel  (Sheriff) 
June  23,  2020  8:51 :02  PM  CDT 
June  23,  2020  8:51 :03  PM  CDT 


Re:  Data  Leak 


From:  Leo.Schmitz@cookcountyil.gov 

To:  Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov> 

Cc:  Bradley  Curry  (Sheriff)  <Bradley.Curry@cookcountyil.gov>,  Marlon  Parks  (Sheriff) 

<Marlon.Parks@cookcountyil.gov>,  Brian  White  (Sheriff) 
<Brian.White@cookcountyil.gov>,  Arunas  Buntinas  (Sheriff) 
<Arunas.Buntinas2@cookcountyil.gov>,  Tarry  Williams  (Sheriff) 

<Tarry.  Williams@cookcountyil.gov> 

Sent:  June  23,  2020  9:48:05  PM  CDT 

Received:  June  23,  2020  9:48:06  PM  CDT 

Ten  four.  Thanks. 

Leo  P.  Schmitz 

Chief  of  Public  Safety 

Cook  County  Sheriffs  Department 


Sent  from  my  iPhone 

E-MAIL  CONFIDENTIALITY  NOTICE:  This  electronic  mail  message,  including  any  attachments,  is  for 
the  intended  recipient! s)  only.  This  e-mail  and  any  attachments  might  contain  information  that  is 
confidential,  legally  privileged,  contains  law  enforcement  database  information,  or  otherwise  protected  or 
exempt  from  disclosure  under  applicable  law.  If  you  are  not  a  named  recipient,  or  if  you  are  named  but 
believe  that  you  received  this  e-mail  in  error,  please  notify  the  sender  immediately  by  telephone  or  return  e- 
mail  and  promptly  delete  this  e-mail  and  any  attachments  and  copies  thereof  from  your  system.  If  you  are 
not  the  intended  recipient  or  are  otherwise  not  authorized  to  further  disclose  this  message  and  its  contents, 
please  be  aware  that  any  copying,  distribution,  dissemination,  disclosure  or  other  use  of  this  e-mail  and  any 
attachments  is  unauthorized  and  prohibited.  Your  receipt  of  this  message  is  not  intended  to  waive  any 
applicable  privilege  or  claim  of  confidentiality,  and  any  prohibited  or  unauthorized  disclosure  is  not  binding 
on  the  sender  or  the  Cook  County  Sheriffs  Office.  Thank  you  for  your  cooperation. 


On  Jun  23,  2020,  at  8:51  PM,  Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov>  wrote: 


Hi, 


Please  let  me  know  if  any  other  questions.  Thanks 
Amar 


"Security  reporter  Brian  Krebs  said  that  the  breach  took  place  at  a  Houston  area 
web  services  company  that  "maintains  several  law-enforcement  data  centers." 


From:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

Sent:  Tuesday,  June  23,  2020  7:10  AM 

Cc:  Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov>;  Adnan  Memon  (Sheriff) 
<Adnan.Memon@cookcountyil.gov>;  Douglas  Maclean  (Sheriff) 
<Douglas.Maclean2@cookcountyil.gov> 

Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

This  is  a  different  article  from  the  International  Association  of  Chiefs  of  Police  that  relates  Netsentinal 
is  a  Houston  service  provider  for  Law  Enforcement. 

https://www.theblaze.com/news/blueleaks-hackers-release-countless-records-on-police-officers-all- 

searchable-by-badge-number 

I  think  our  only  risk  from  doxing  would  be  workforce.  I  pulled  the  attached  reports  last  Friday  and 
provided  them  to  Chuck  at  Homeland  for  review. 


From:  Keith  Morrison  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:45  AM 

To:  Douglas  Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


From:  Keith  Morrison  (Sheriff)  <Keith. Morrison@cookcountvil.gov> 

Sent:  Tuesday,  June  23,  2020  6:20  AM 

To:  Douglas  Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov>:  Amar  Patel  (Sheriff) 
<Amar. Patel@cookcountvil.gov>:  Adnan  Memon  (Sheriff)  <Adnan. Memon@cookcountvil.gov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Deputy  CIO  Maclean, 


Thanks, 


Morrison 


From:  Leo  Schmitz  (Sheriff)  <Leo. Schmitz@cookcountyil.gov> 

Sent:  Tuesday,  June  23,  2020  7:52  PM 

To:  Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov>;  Bradley  Curry  (Sheriff) 
<Bradley.Curry@cookcountyil.gov>;  Marlon  Parks  (Sheriff)  <Marlon.Parks@cookcountyil.gov>;  Brian 
White  (Sheriff)  <Brian.White@cookcountyil.gov>;  Arunas  Buntinas  (Sheriff) 

<Arunas.  Buntinas2@cookcountyil.gov> 

Subject:  Fwd:  Data  Leak 

FYI 

Leo  P.  Schmitz 

Chief  of  Public  Safety 

Cook  County  Sheriffs  Department 


Sent  from  my  iPhone 

E-MAIL  CONFIDENTIALITY  NOTICE:  This  electronic  mail  message,  including  any 
attachments,  is  for  the  intended  recipient(s)  only.  This  e-mail  and  any  attachments  might 
contain  information  that  is  confidential,  legally  privileged,  contains  law  enforcement  database 
information,  or  otherwise  protected  or  exempt  from  disclosure  under  applicable  law.  If  you  are 
not  a  named  recipient,  or  if  you  are  named  but  believe  that  you  received  this  e-mail  in  error, 
please  notify  the  sender  immediately  by  telephone  or  return  e-mail  and  promptly  delete  this  e- 
mail  and  any  attachments  and  copies  thereof  from  your  system.  If  you  are  not  the  intended 
recipient  or  are  otherwise  not  authorized  to  further  disclose  this  message  and  its  contents,  please 
be  aware  that  any  copying,  distribution,  dissemination,  disclosure  or  other  use  of  this  e-mail  and 
any  attachments  is  unauthorized  and  prohibited.  Your  receipt  of  this  message  is  not  intended  to 
waive  any  applicable  privilege  or  claim  of  confidentiality,  and  any  prohibited  or  unauthorized 
disclosure  is  not  binding  on  the  sender  or  the  Cook  County  Sheriffs  Office.  Thank  you  for  your 
cooperation. 

Begin  forwarded  message: 


From:  Nick  Roti  <nroti@chicago-hidta.org> 

Date:  June  23,  2020  at  7:45:28  PM  CDT 

To:  "Leo  Schmitz  (Sheriff)"  <Leo. Schmitz@cookcountyil.gov> 

Subject:  Fwd:  Data  Leak 


External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper 
judgment  and  caution  when  opening  attachments,  clicking  links,  or 
responding  to  this  email. 


FYI 


Nicholas  J.  Roti 
Executive  Director 
Chicago  HIDTA 
312.448.5666  Office 
312.617.7237  Cell 
nroti@chicago-hidta.org 


Begin  forwarded  message: 


From:  "Leopold,  Daniel  J"  <Daniel.J.Leopold@ice.dhs.gov> 

Date:  June  23,  2020  at  6:40:39  PM  CDT 
To:  Brian  Wolfe  <mbwolfe@fbi.gov>,  Leo  Panepinto 
<Leo.Panepinto@chicagopolice.org>,  "Quinn,  Patrick" 
<patrick.quinn@chicagopolice.org>,  Aaron  Kustermann 
<aaron_kustermann@isp.state.il.us>,  Darrell  Aders 
<darrell_aders@isp. state. il.us>,  "Workman,  Byron" 
<B5a-0n.W0rkman@illin0is.g0v>,  Alison  Jacobs 
<alison.l.jacobs2.mil@mail.mil>,  James  G  Probst 
<j ames.g.probst.mil@mail.mil>,  "dale.k.kirkendoll.mil@mail.mil" 
<dale.k.kirkendoll.mil@mail.mil>,  Steven  Artino 
<steven.t.artino@cbp.dhs.gov>,  "robert.w.harris@dhs.gov" 
<robert.w.harris@dhs.gov>,  Christian  Hoffman 
<Christian.M.Hoffman@usdoj.gov>,  Jim  Crotty 
<james.m.crotty@usdoj.gov>,  Patrick  O'Dea 
<patrick.j.o'dea@usdoj.gov>,  Nick  Roti  <nroti@chicago-hidta.org>, 
Jessica  Ipema  <Jessica.m.ipema@usdoj.gov>, 
"MARK.DELIA@ILLINOIS.GOV" 

<M ARK. DELI A@ILLIN OIS . GOV >,  Robert  Graves 
<rmgraves@fbi.gov>,  "Worniak,  Adam  T.  (CG)  (LBI)" 
<atwomiak@fbi.gov>,  "Krumrei,  Erich  W.  (CG)  (LBI)" 
<ewkrumrei@fbi.gov>,  Jeffrey  Rauch  <jdrauch@fbi.gov>,  "Chellberg, 
Samantha  (CG)  (LBI)"  <schellberg@fbi.gov>,  "Justiniano,  Robert 
(CG)  (LBI)"  <rjustiniano@fbi.gov>,  "JVButhom@uspis.gov" 
<JVButhom@uspis.gov> 

Cc:  Daniel  Leopold  <daniel.j.leopold@ice.dhs.gov> 

Subject:  Data  Leak 


All,  see  below  link  related  to  a  massive  data  breach  exposing  24  years' 
worth  of  documents,  PII,  RPIs,  etc.  from  over  200  federal,  state,  and 
local  police  departments.  Apparently,  there  is  270  gigs  of  data. 

https://krebsonsecurity.com/2020/06/blueleaks-exposes-files-ffom- 

hundreds-of-police-departments/ 

Thanks, 

Dan 

Daniel  J.  Leopold  |  Chief  Intelligence  Officer 

DHS  -  ICE  |  Homeland  Security  Investigations  |  SAC  Chicago 

One  Tower  Lane,  Suite  1600  |  Oakbrook  Terrace,  Illinois  60181 


(630)441-8343  (c)(  |  (630)  574-4121  |  daniel.j.leopold@ice.dhs.gov 
Illinois]  Indiana  (Wisconsin 

WARNING:  This  email  and  any  attachments  are 
UNCLASSIFIED//FOR  OFFICIAL  USE  ONLY  (U//FOUO).  It 
contains  information  that  may  be  exempt  from  public  release  under  the 
Freedom  of  Information  Act  (5  U.S.C.  552).  It  is  to  be  controlled, 
stored,  handled,  transmitted,  distributed,  and  disposed  of  in  accordance 
with  DHS  policy  relating  to  FOUO  information  and  is  not  to  be 
released  to  the  public  or  other  personnel  who  do  not  have  a  valid 
"need-to-know"  without  prior  approval  of  an  authorized  DHS  official. 
No  portion  of  this  email  should  be  furnished  to  the  media,  either  in 
written  or  verbal  form.  If  you  are  not  an  intended  recipient  or  believe 
you  have  received  this  communication  in  error,  please  do  not  print, 
copy,  retransmit,  disseminate,  or  otherwise  use  this  information. 

Please  inform  the  sender  that  you  received  this  message  in  error  and 
delete  the  message  from  your  system. 


Re:  Data  Leak 


To:  Amar  Patel  (Sheriff),  Bradley  Curry  (Sheriff),  Marlon  Parks  (Sheriff),  Brian  White 

(Sheriff),  Arunas  Buntinas  (Sheriff) 

Cc:  Bradley  Curry  (Sheriff),  Marlon  Parks  (Sheriff),  Brian  White  (Sheriff),  Arunas  Buntinas 

(Sheriff),  Tarry  Williams  (Sheriff) 

Sent:  June  23,  2020  9:48:06  PM  CDT 

Received:  June  23,  2020  9:48:06  PM  CDT 


Tasks 


From: 

To: 

Sent: 

Received: 

Attachments: 

Attached. 


Jonathan  Springborn  (Sheriff)  <Jonathan. Springborn@cookcountyil.gov> 
Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

June  23,  2020  10:09:34  PM  CDT 
June  23,  2020  10:09:35  PM  CDT 
WORK_062320.xlsx 


Jonathan  Springborn 
Cook  County  Sheriffs  Office 
Sheriffs  Information  Technology  Unit 
3026  S.  California,  Chicago,  IL  60608 
Jonathan.Springborn(S)cookcounvil.gov 

(773)  674-6850  -  Sheriff  Help  Desk 
(312)  339-2995 -Mobile 
www.cookcountysheriff.org 


Tasks 


From: 


To: 

Sent: 

Received: 

Attachments: 

Attached. 


Jonathan  Springborn  (Sheriff)  </0=EXCHANGELABS/OU=EXCHANGE 
ADMINISTRATIVE  GROUP 

(FYDIBOHF23SPDLT)/CN=RECIPIENTS/CN=32F2AOA9AA124C638CA1784E3422B46 
4-JONATHAN  SP> 

Keith  Morrison  (Keith.Morrison@cookcountyil.gov)  <Keith.Morrison@cookcountyil.gov> 
June  23,  2020  10:09:34  PM  CDT 
June  23,  2020  10:09:00  PM  CDT 
WORK_062320.xlsx 


Jonathan  Springborn 
Cook  County  Sheriffs  Office 
Sheriffs  Information  Technology  Unit 
3026  S.  California,  Chicago,  IL  60608 
Jonathan.Springborn(S)cookcounvil.gov 

(773)  674-6850  -  Sheriff  Help  Desk 
(312)  339-2995 -Mobile 
www.cookcountysheriff.org 


Good  Morning!  The  Power  of  Information  -  Law  Enforcement  News  of  the  Day: 
June  24,  2020 

From:  Ness  and  Associates  Law  Enforcement  Daily  News  <jness23@cox.net> 

To:  Phyllis  <phyllis.tillis@cookcountyil.gov>,  Phyllis  Tillis  (Sheriff) 

<Phyllis.Tillis@cookcountyil.gov> 

Sent:  June  24,  2020  5:59:51  AM  CDT 

Received:  June  24,  2020  5:59:59  AM  CDT 

External  Message  Disclaimer 

i  This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 


View  this  email  in  your  browser 


Your  daily  source  for  what's  interesting  and  news  worthy  around  the  country  and 
the  rest  of  the  world 


Daily  News  &  Updates  for  Wednesday 
June  24,  2020 


THOUGHT  FOR  THE  DAY 


“When  we  long  for  life  without  difficulties, 
remind  us  that  oaks  grow  strong 
in  contrary  winds 

and  diamonds  are  made  under  pressure.” 
Peter  Marshall 


Minneapolis  Police  Chief  Medaria  Arradondo 
on  George  Floyd's  killing,  policies  during 
protests  and  reform  for  his  department 

On  Memorial  Day,  a  white  Minneapolis  police  officer  knelt  on  a  black  man's  neck 
until  he  was  unresponsive.  The  killing  of  George  Floyd  sparked  the  protests  we've 
seen  around  the  country.With  Minneapolis  on  edge  and  under  scrutiny,  the 
pressure  is  on  the  city's  police  chief,  Medaria  Arradondo,  a  30-year  veteran  and 
the  first  black  man  to  head  the  mostly  white  police  department.  He  fired  the  four 
officers  involved  within  24  hours.  We  spoke  with  the  chief  remotely,  discussing  the 
events  of  May  25,  the  video  that  ignited  it  all  and  the  police  response,  which 
started  with  a  lie. 


Want  to  reform  the  police?  Hire  more  women 

It  was  a  moment  that  captured  national  attention  and  revealed  an  important 
lesson  about  police  reform. 

A  Fort  Lauderdale,  Florida,  policeman,  facing  off  against  a  line  of  yelling 
demonstrators,  sticks  his  finger  in  the  face  of  a  protester.  He  then  turns  toward  a 
kneeling  woman,  her  hands  raised  in  protest.  The  officer  suddenly  lunges  and 
shoves  her. 

Then,  a  female  officer  appears.  She  swats  her  male  colleague  back  toward  a  line 
of  patrol  cars,  waving  her  arm  and  appearing  to  upbraid  him  for  what  he  did. 
"Thank  you!"  a  protester  shouts  at  Officer  Krystle  Smith,  who  won  praise  for  her 
actions  on  social  media  and  from  police  leaders  around  the  country. 

Neither  Smith  nor  Officer  Steven  Pohorence,  who  is  suspended  pending  an 
outside  investigation,  were  allowed  to  comment  on  the  incident. 


"I  was  proud  of  her,"  said  Ivonne  Roman,  the  former  police  chief  in  Newark,  New 
Jersey,  who  has  been  fighting  for  years  to  push  her  profession  to  hire  more 
women.  "That  is  why  we  need  more  women  in  policing.  Statistically,  they  do  not 
escalate;  they  de-escalate." 

As  protests  over  the  police  killing  of  George  Floyd  have  refocused  national 
attention  on  police  abuses  and  use  of  force,  law  enforcement  experts  and  leaders 
say  one  powerful  reform  would  be  simple:  Hire  more  women. 

Women  make  up  only  about  one  out  of  every  eight  sworn  police  officers 
nationwide,  according  to  federal  statistics. 

\ 


LAPD  officers  call  in  absent  for  nearly  700 


transit-policing  shifts  in  one  week 


Dozens  of  policing  shifts  on  Los  Angeles  County’s  transit  system  went  unfilled  last 
week  after  Los  Angeles  Police  Department  officers  called  in  absent  nearly  700 
times,  the  Metropolitan  Transportation  Authority  said. 

The  absences,  for  overtime  shifts  with  premium  pay,  came  after  Chief  Michel 
Moore  temporarily  froze  overtime  for  the  LAPD. 

The  department  spent  $40  million  in  overtime  during  a  week  of  protests  over 
police  brutality,  systemic  racism  and  the  death  of  George  Floyd,  Moore  told 
officers  earlier  this  month.  He  said  future  overtime  would  be  paid  out  with  time  off, 
rather  than  cash. 

The  LAPD’s  $369-million,  five-year  contract  to  patrol  Metro  buses  and  trains  in 
L.A.  includes  an  agreement  to  staff  1 ,008  shifts  per  week,  said  LAPD  spokesman 
Josh  Rubenstein.  Those  shifts  are  filled  by  officers  working  overtime,  he  said. 
From  June  12  to  June  19,  LAPD  officers  called  in  absent  for  696  transit  policing 
shifts,  Metro  spokesman  Rick  Jager  said.  Most  were  filled  through  substitutes,  but 
171  went  unfilled,  he  said. 


Saying  Chicago  police  uphold  ‘racist  and 
white  supremacist  values,’  DePaul  tutors 
refuse  to  work  with  officers  taking  classes,  call 
for  university  to  cut  ties  with  department 

After  weeks  of  student  calls  to  end  educational  programs  that  serve  members  of 
the  Chicago  Police  Department,  DePaul  University  Provost  Salma  Ghanem  turned 
aside  the  demands  on  Monday,  saying  in  a  statement  that  “the  actions  of  a  few  do 
not  represent  the  (CPD  officers)  we  teach.” 

The  provost’s  statement  also  included  an  account  from  an  unnamed  police  officer 
who  said  she  was  “devastated”  by  the  students’  appeal. 

“As  a  CPD  Latina  I  am  proud  to  be  who  I  am  and  for  the  past  12  years  have 
worked  tirelessly  throughout  my  career  to  make  a  difference  and  I  can  bet  my  life 


savings  that  many  officers  (enrolled  at  DePaul)  share  the  same  feelings,”  she 
wrote. 

Ghanem’s  statement  didn’t  sit  well  with  some  who  want  DePaul  to  sever  ties  with 
CPD  and  Chicago’s  Fraternal  Order  of  Police  Lodge  7.  Junior  Aneesah  Shealey, 
who  was  one  of  the  first  to  criticize  educational  programs  the  school  offers  to  the 
police  union,  said  students  will  continue  to  organize  to  reverse  the  decision. 
“We’re  trying  to  emphasize  that  you  can’t  separate  the  person  from  the  career,” 
she  said.  “It  doesn’t  matter  that  there  are  good  cops.  They’re  still  protecting  the 
ones  committing  the  acts  of  violence.” 

A  DePaul  spokeswoman  said  Ghanem  was  not  available  for  an  interview,  and 
declined  to  provide  other  officials  to  answer  questions  on  the  school’s  behalf. 


Black  men  plan  Southfield  Michigan  march  to 


protest  police  brutality 


SOUTHFIELD,  Mich.  (AP)  —  A  march  designed  to  unite  Black  men  while 
protesting  police  brutality  and  racial  injustice  is  scheduled  for  next  week  in 
suburban  Detroit. 

Organizers  say  the  planned  peaceful  protest  on  June  28  will  begin  at  Hope  United 
Methodist  Church  in  Southfield,  just  north  of  Detroit,  and  end  at  the  city’s 
municipal  offices. 

A  voter  registration  drive  will  be  held,  and  participants  also  will  be  encouraged  to 
complete  the  2020  census. 

Peaceful  protests,  demonstrations  and  unrest  have  spread  to  cities  around  the 
U.S.  following  the  May  25  death  of  George  Floyd  in  Minneapolis.  A  white  police 
officer  pressed  his  knee  into  Floyd’s  neck  for  several  minutes,  even  after  the 
handcuffed  Black  man  stopped  moving  and  pleading  for  air. 


Chicago’s  violent  weekend  renews  search  for 
answers  in  a  tense  city,  points  again  to 
entrenched  problems 

New  Chicago  police  Superintendent  David  Brown  has  been  in  his  post  for  just  two 
months,  but  his  walk  to  a  lectern  at  police  headquarters  had  a  familiar  feel 
Monday. 

Another  weekend  of  stunning  bloodshed  in  Chicago  had  given  way  to  another 
round  of  police  and  city  leaders  grasping  for  explanations. 

“On  the  heels  of  Father’s  Day,  I  come  to  you  again  with  obviously  a  high  level  of 
frustration  and  disappointment,”  Brown  said  at  a  press  briefing. 

This  time,  on  the  first  official  summer  weekend  of  the  year,  it  was  106  people  shot, 
14  of  them  fatally  —  including  a  3-year-old  boy. 


The  tally  between  Friday  afternoon  and  early  Monday  marked  the  most  people 
shot  in  one  weekend  here  since  at  least  2012,  and  the  violence  took  a  particular 
toll  on  children.  Twelve  of  those  shot  were  younger  than  18  years  old.  Five  of 
them  died,  including  two  walking  into  their  backyard  after  going  to  get  candy  at  a 
corner  shop. 

Six  shootings  involved  three  or  more  victims.  One  drive-by  shooting  early  Monday 
in  the  East  Garfield  Park  neighborhood  injured  five,  including  a  16-year-old  girl 
who  was  left  in  critical  condition. 

And  while  shootings  were  seen  across  the  city,  those  who  work  at  the  front  lines 
of  reducing  violence  also  were  left  to  consider  what’s  happening  on  blocks  that 
have  borne  the  brunt  of  the  problem  for  decades.  Chicago  is  an  agitated  place, 
they  said,  dealing  with  the  stress  of  a  global  pandemic,  recent  civil  unrest  and  the 
fallout  from  decades  of  neglect  and  abandonment  in  some  neighborhoods. 


Massive  attack  on  police:  'Blueleaks1  hackers 
release  'hundreds  of  thousands'  of  private 
records  on  officers 


Hackers  have  leaked  highly  sensitive  police  files  from  over  200  police 
departments  across  the  country,  according  to  a  Business  Insider  report  Monday. 


All  files  are  reportedly  searchable  by  badge  number.  Activist  group  DDoSecrets 
published  what  the  outlet  calls  "hundreds  of  gigabytes'  worth  of  potentially 
sensitive  files"  from  police  departments  across  the  United  States.  The  group  has 
called  the  information  dump  "BlueLeaks." 

The  group  compiled  the  records,  disseminating  them  into  a  searchable  database 
that  can  pull  up  private  information  from  a  police  badge  number.  Many  of  the  files 
include  information  such  as  memos,  emails,  and  officers'  personal  information. 

The  group  shared  information  on  Twitter  regarding  the  data  dump. 

It  wrote,  "RELEASE:  #BlueLeaks  (269  GB)  Ten  years  of  data  from  over  200  police 
departments,  fusion  centers  and  other  law  enforcement  training  and  support 
resources.  Among  the  hundreds  of  thousands  of  documents  are  police  and  FBI 
reports,  bulletins,  guides  and  more." 


‘The  officers  feel  like  they  can’t  win’:  Tampa 
chief  responds  to  police  criticism 

At  a  brief  press  conference  Monday,  Tampa  police  Chief  Brian  Dugan  painted  a 
picture  of  a  beleaguered  police  force,  worn  down  by  weeks  of  protests  and  media 
scrutiny. 

“The  police,  we  always  have  everybody’s  back  and  nobody  has  our  back,”  he 
said.  “Right  now  the  officers  feel  like  they  can’t  win.  And  I  would  have  to  agree 
with  them.” 


He  said  demonstrations  against  police  brutality  that  have  blocked  traffic  and 
sometimes  led  to  tense  stand-offs  have  created  a  dilemma  for  police.  Officers 
have  kept  their  distance  from  recent  protests  in  an  effort  to  diffuse  tension,  but 
Dugan  said  that  wasn’t  sustainable. 

“Police  are  in  a  very  tough  spot  —  if  we  show  up  to  people  who  are  just  merely 
exercising  their  First  Amendment  rights,  it  turns  into  a  clash  and  police  are  the 
bad  guys,”  he  said.  “But  we  also  now  have  people  who  are  complaining  about  the 
lack  of  a  police  presence  at  these  protests.” 

He  highlighted  two  recent  incidents  unrelated  to  the  protests  where  officers  were 
injured:  On  Saturday  night,  officers  responded  to  calls  of  shots  fired  at  15th  Street 
N  and  26th  Avenue  N,  only  to  encounter  a  crowd  of  hundreds  who  threw  bottles  at 
officers  and  jumped  on  a  police  vehicle.  One  officer  was  struck  on  the  left  side  of 
his  face  and  went  to  the  hospital  with  a  laceration.  No  shooting  victim  was  found 
and  Dugan  described  it  as  an  “ambush”  at  a  block  party. 


41  Cities,  Many  Sources:  How  False  Antifa 
Rumors  Spread  Locally 

In  recent  weeks,  as  demonstrations  against  racism  spread  across  the  country, 
residents  in  at  least  41  U.S.  cities  and  towns  became  alarmed  by  rumors  that  the 
loose  collective  of  anti-fascist  activists  known  as  antifa  was  headed  to  their  area, 
according  to  an  analysis  by  The  New  York  Times.  In  many  cases,  they  contacted 
their  local  law  enforcement  for  help. 

In  each  case,  it  was  for  a  threat  that  never  appeared. 

President  Trump  has  spread  some  unfounded  rumors  about  antifa  to  a  national 
audience  —  including  his  accusation,  without  evidence,  that  a  75-year-old  Buffalo 
protester  who  was  hospitalized  after  being  knocked  down  by  a  police  officer  could 
be  “an  antifa  provocateur.” 

But  on  the  local  level,  the  source  of  the  false  information  has  usually  been  more 


subtle,  and  shows  the  complexity  of  stunting  misinformation  online.  The  bad 
information  often  first  appears  in  a  Twitter  or  Facebook  post,  or  a  YouTube  video 
there.  It  is  then  shared  on  online  spaces  like  local  Facebook  groups,  the 
neighborhood  social  networking  app  Nextdoor  and  community  texting  networks. 
These  posts  can  fall  under  the  radar  of  the  tech  companies  and  online  fact 
checkers. 


Garcetti  under  fire  for  handling  of  police 
brutality  protests 


The  police  union  has  called  him  unstable.  Activists  accuse  him  of  supporting  racist 


institutions.  Even  longtime  allies  said  his  decisions  during  the  recent  protests  over 
police  brutality  hurt  Los  Angeles’  communities  of  color. 

Mayor  Eric  Garcetti’s  handling  of  the  demonstrations  and  his  subsequent  actions 
drew  criticism  from  an  array  of  groups,  wide  pushback  unseen  during  his  seven 
years  leading  the  city. 

Garcetti,  known  for  avoiding  political  risk,  has  appeared  at  times  whipsawed  by 
the  protests  and  their  aftermath. 

“When  you’re  being  fired  on  politically  from  all  sides,  not  sure  exactly  how  to  move 
because  you  know  you  can’t  make  everybody  happy?”  said  Isaac  Bryan,  director 
of  the  Black  Policy  Project  at  UCLA.  “I  can  imagine  that’s  a  frustrating  place  for 
him.” 

As  police  and  demonstrators  clashed  in  the  Fairfax  district  last  month,  Garcetti 
said  he  didn’t  plan  to  request  the  National  Guard.  Hours  later,  he  did.  Angering 
the  police  union,  he  unveiled  plans  to  cut  the  Police  Department,  after  defending 
its  size  days  earlier. 


The  Latest:  Police:  2  dead,  7  wounded  in  N 
Carolina  shooting 

CHARLOTTE,  N.C.  —  Authorities  in  North  Carolina  say  a  shooting  at  an 
impromptu  block  party  has  left  two  people  dead  and  seven  others  wounded. 
Charlotte-Mecklenburg  Police  Deputy  Chief  Johnny  Jennings  told  reporters  early 
Monday  the  shooting  happened  around  midnight  at  a  block  party  that  was  a 
continuation  of  Juneteenth  celebrations.  Jennings  said  police  responding  to  a 
pedestrian  call  found  hundreds  of  people  in  the  streets. 

After  authorities  arrived,  several  shots  were  fired  and  the  crowd  scattered. 
Jennings  said  five  people  were  hit  by  cars  while  running  away  from  the  shooting. 
He  said  there  was  evidence  of  multiple  shooters. 

Further  details  weren’t  immediately  available. 


Ex-FBI  agent  charged  with  hoarding  top-secret 
government  documents 

A  former  FBI  special  agent  who  worked  for  years  in  Chicago’s  organized  crime 
division  has  been  charged  with  stealing  sensitive  government  documents  and 
hoarding  them  in  his  home  after  retirement. 

Yen  Cham  Yung,  who  achieved  top  government  security  clearance  during  his 
lengthy  career,  was  arrested  in  Colorado  earlier  this  week  and  is  scheduled  to  be 
brought  to  Chicago  to  face  the  charges. 

Yung,  57,  was  accused  in  a  criminal  complaint  unsealed  Tuesday  of  illegally 
keeping  hundreds  of  documents  without  consent,  including  sensitive  information 
about  undercover  informants,  surveillance  of  gang  activity  and  email  threads 
between  FBI  supervisors  concerning  organized  crime  investigations. 

The  complaint  also  alleged  Yung  violated  national  security  protocols  by  keeping  a 
copy  of  a  memorandum  of  understanding  between  the  CIA  and  FBI  “regarding  the 


activities  of  those  agencies  overseas  and  domestically.” 

The  memorandum  had  been  accessed  in  2009  at  the  Chicago  FBI  headquarters 
by  someone  using  Yung’s  credentials,  according  to  the  complaint. 

The  charges  do  not  allege  Yung  sold  or  disseminated  any  of  the  information. 


Officers  find  mannequin  dressed  in  police 
uniform  hanging  from  Jacksonville  overpass 

JACKSONVILLE,  Fla.  -  Jacksonville  police  on  Saturday  morning  found  a 
mannequin  dressed  in  a  law  enforcement  uniform  hanging  from  an  overpass, 
authorities  said. 

About  6:20  a.m.,  according  to  the  Jacksonville  Sheriff’s  Office,  police  were  called 


to  a  potential  suicide  by  hanging  on  the  Interstate  95  overpass  near  Zoo  Parkway. 
Police  said  they  then  discovered  it  was  actually  a  mannequin  dressed  in  an  New 
York  Police  Department  uniform  with  a  pig  mask. 

“About  6  a.m.,  we  was  coming  on  95,  and  first,  I  thought  it  was  a  body  and  my 
heart  completely  dropped,”  said  Jacksonville  resident  Lamont  Ross,  who  is  a 
medical  transportation  driver,  along  with  his  wife.  “Immediately  we  turned  around.” 
Kamri  Merriweather  also  saw  the  mannequin  on  her  way  home  from  working  a  12- 
hour  shift. 

“My  entire  heart  dropped.  It  just  sank.  I  was  not  sure  what  to  do.  I  was  nerve 
wrecked,  scared  and  at  the  same  time  confused.  I  could  not  believe,  out  of  my 
entire  life,  I  would  ever  see  anything  like  that,”  Merriweather  said. 

Detectives  said  the  mannequin  will  be  processed  for  DNA. 


30  cases  of  deadly  police  force  will  get  state 
review  to  ensure  independent  investigation 


A  statewide  investigation  will  be  done  into  30  cases  where  police  killed  people  this 
year  to  ensure  law  enforcement  agencies  are  complying  with  a  new  law  requiring 
independent  investigations,  Washington  State  Attorney  General  Bob  Ferguson 
announced  Tuesday. 

The  inquiry  was  prompted  by  Pierce  County  Sheriff’s  Department’s  lapses  to 
follow  Initiative  940  while  looking  into  the  March  3  death  of  Manuel  Ellis  as  he  was 
detained  by  Tacoma  police. 

“Pierce  County’s  admitted  failure  to  comply  with  the  requirements  of  1-940  is 
deeply  troubling,”  Ferugson  said  in  a  statement.  “I  hope  our  inquiry  will  find  that 
law  enforcement  agencies  across  the  state,  unlike  Pierce  County,  are  following 
the  law  that  requires  independent,  transparent  investigations  into  the  use  of 
deadly  force.” 

There  are  no  known  instances  of  other  investigations  not  complying  with  the  law, 
Ferguson  said. 

Once  the  review  is  complete,  the  Attorney  General’s  Office  will  release  its  findings 
to  the  public. 

No  timeline  was  given. 


GOP  senator  introduces  measure  to  curb  legal 
shield  for  law  enforcement 

GOP  Senator  Mike  Braun  of  Indiana  is  rolling  out  legislation  aimed  at  reforming 
the  powerful  legal  shield  that  protects  police  officers  and  other  government 
officials  from  being  sued  for  misconduct,  an  issue  that  has  become  a  focal  point  in 
the  debate  over  policing  raging  across  the  country. 

The  measure  to  be  introduced  by  Braun  on  Tuesday  targets  the  legal  doctrine 
known  as  qualified  immunity,  which  protects  government  officials  from  civil 
lawsuits  unless  victims  can  show  officers  violated  "clearly  established" 
constitutional  or  statutory  rights.  Created  by  the  Supreme  Court,  the  doctrine  has 
faced  heightened  criticism  in  recent  years  due  to  the  high  bar  victims  must  reach 
to  hold  law  enforcement  accountable  for  use  of  excessive  force. 

Braun's  proposal  scales  qualified  immunity  back  and  says  that  government 


officials,  including  police,  can  claim  qualified  immunity  only  when  they  can  prove 
their  alleged  conduct  had  previously  been  authorized  by  federal  or  state  law,  or 
when  a  court  has  found  the  alleged  unlawful  conduct  was  consistent  with  the  U.S. 
Constitution  and  federal  laws. 

The  bill  would  also  ensure  that  municipalities  are  held  accountable  for  their 
employees'  misconduct. 

"It's  time  Congress  does  their  job  to  establish  a  qualified  immunity  law  that 
defends  law  enforcement,  while  protecting  the  rights  of  the  people,"  Braun  said  in 
a  statement.  The  Indiana  senator  called  the  criteria  law  enforcement  must  satisfy 
to  assert  qualified  immunity  under  his  bill  "a  meaningful  change  that  will  help  law 
enforcement  and  the  citizens  they  protect." 
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Top  Senate  Democrats  Dismiss  Republican  Policing 
Reform  Bill 

The  AP  (6/23,  Mascaro)  reports  Congress  is  "hitting  an  impasse  on 
aolicing  legislation,  as  key  Senate  Democrats  on  Tuesday  opposed  a 
Republican  proposal  as  inadequate,  leaving  the  parties  to  decide 
whether  to  take  on  the  hard  job  of  negotiating  a  compromise  or  walk 
away."  Ahead  of  a  test  vote  Wednesday,  Senate  Majority  Leader 
McConnell  "acknowledged  it  may  fall  short,"  and  the  GOP  bill's  author, 
sen.  Tim  Scott  (R-SC),  "warned  against  a  partisan,  political  debate  that 
chisels  away  confidence  in  the  nation's  institutions."  Reuters 
[6/23,  Morgan)  similarly  says  "Democrats  and  Republicans.. .found 
themselves  in  a  partisan  deadlock  on  Tuesday." 

AP-NORC  Poll:  Nearly  All  Americans  Back  Some  Kind  Of 
Criminal  Justice  Reform.  The  AP  I  B(6/23,  Long,  Fingerhut)  reports  that  Americans  "overwhelmingly  want  clear  standards 
on  when  police  officers  may  use  force  and  consequences  for  officers  who  do  so  excessively,  according  to  a  new  poll  that  finds 
nearly  all  Americans  favor  at  least  some  level  of  change  to  the  nation's  criminal  justice  system."  The  new  AP-NORC  poll  "also 
finds  there  is  strong  support  for  penalizing  officers  who  engage  in  racially  biased  policing." 

Confronting  Nazi  Legacy  Part  Of  German  Police  Training 

The  New  York  Times  (6/23,  Bennhold,  Eddy)  reports  that  "visiting  a  former  concentration  camp  is  mandatory  for  every 


future  police  officer  in  Berlin."  To  the  Times,  it  is  "one  of  the  ways  in  which  policing  was  fundamentally  overhauled  in  Germany 
afterWorld  Warll." 

Rhode  Island  Governor  Signs  Ban  On  3D-Printed  Weapons,  "Ghost  Guns" 

The  AP  (6/23,  Pratt)  reports  that  Rhode  Island  Gov.  Gina  Raimondo  "on  Tuesday  signed  into  law  bills  that  ban  3D-printed 
guns  and  so-called  'ghost  guns'  in  the  state."  The  bills  "are  'a  matter  of  public  health,'  she  said."  The  bills  "were  approved  by 
the  legislature  last  week,"  and  "make  it  illegal  to  manufacture,  import,  sell,  ship,  deliver,  possess,  transfer  or  receive  any  such 
firearms.  Anyone  who  violates  the  ban  and  is  convicted  could  serve  up  to  10  years  in  prison  and  faces  fines  of  up  $10,000.  The 
laws  take  effect  in  30  days." 

Seattle,  Washington  To  End  Anti-Loitering  Law 

Fox  News  (6/23,  Carter)  reports,  "Seattle  is  moving  to  end  a  longstanding  city  law  that  allowed  police  to  arrest  someone 
for  loitering,  if  they  are  also  suspected  of  being  a  possible  drug  offender  or  sex  worker."  According  to  Fox  News,  "The  twin  bills, 
passed  unanimously  by  the  Seattle  City  Council  Monday,  effectively  block  authorities  from  arresting  someone  for  loitering  in 
relation  to  a  drug  or  a  prostitution  inquiry.  Both  laws,  according  to  the  Chicago-Kent  Law  Review,  have  historically  targeted 
people  of  color." 

Georgia  Lawmakers  Pass  Bills  On  Hate  Crimes,  Enhanced  Police  Protections 

The  AP  (6/23,  Nadler,  Amy)  reports,  "Georgia's  legislature  on  Tuesday  passed  hate  crimes  legislation  deemed  essential  by 
business  and  many  political  leaders,  sending  the  measure  to  Gov.  Brian  Kemp's  desk.  The  price  Republicans  exacted  for  moving 
that  legislation  forward  was  simultaneous  passage  of  a  separate  bill  that  would  mandate  penalties  for  crimes  targeting  police 
and  other  first  responders."  According  to  the  AP,  "The  action  comes  after  Senate  Republicans  had  added  police  as  a  protected 
class  to  the  hate  crimes  legislation  last  week  in  committee,  but  then  later  moved  those  protections  to  a  separate  bill  in  a  deal 
between  the  parties.  Democrats  on  Tuesday  voted  overwhelmingly  against  House  Bill  838,  which  includes  the  increased 
protections  for  first  responders.  The  hate  crimes  legislation,  House  Bill  426,  had  bipartisan  support." 


The  impact  of  an  officer's  line-of-duty  injury  may  continue  beyond  the  initial  event  and  hospitalization.  Agencies 
can  prepare  to  provide  resources  such  as  behavioral  health  and  wellness  or  peer  support  services  to  officers  and 
their  families.  The  Line-of-Duty  Serious  Injury  Considerations  document  and  Concepts  &  Issues  paper  from  the 
IACP  Law  Enforcement  Policy  Center  provides  guidelines  for  agencies  to  consider. 
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CRIME  &  DRUGS 


Law  Enforcement  Concerned  About  Rash  Of  Gun-Store  Robberies 

Politico  (6/23,  Swan)  reports,  "A  rash  of  gun-store  burglaries  has  alarmed  law  enforcement  officials,  and  comes  amid 
widespread  protests  that  have  been  accompanied  by  incidents  of  looting  and  vandalism  across  the  country."  According  to 
Politico,  "In  the  last  days  of  May  and  first  week  of  June,  there  were  more  than  90  attempted  or  successful  burglaries  of  gun 
stores,  according  to  the  Bureau  of  Alcohol,  Tobacco,  and  Firearms  (ATF).  More  than  1,000  guns  were  stolen  in  that  window  of 
time,  the  bureau's  assistant  director  of  field  operations  Tom  Chittum  told  POLITICO.  'It's  a  lot  of  guns,'  Chittum  said  in  an 
interview.  'It's  the  biggest  spike  I  have  ever  seen  of  gun  store  burglaries.'"  Chittum  "said  investigations  into  the  surge  of  gun 
store  burglaries  are  underway,  and  that  some  of  the  burglaries  appeared  to  be  part  of  broader  looting.  Other  cases,  he  added, 
may  have  been  the  work  of  opportunists." 


Gun  Violence  Spikes  In  New  York  City 

The  New  York  Times  (6/23,  Southall,  Macfarquhar)  reports,  "It  has  been  nearly  a  quarter  century  since  New  York  City 
experienced  as  much  gun  violence  in  the  month  of  June  as  it  has  seen  this  year."  The  city  "logged  125  shootings  in  the  first 
three  weeks  of  the  month,  more  than  double  the  number  recorded  over  in  same  period  last  year,  police  data  show.  Gunmen 
opened  fire  during  house  parties,  barbecues,  dice  games,  and  carried  out  coldly  calculated  street  executions."  New  York  "is  not 
alone.  Shootings  are  on  the  rise  in  other  big  cities  across  the  country,  including  Chicago  and  Minneapolis,  a  trend  that  some 
conservatives  have  seized  on  to  argue  against  the  recent  demands  of  protesters  to  cut  police  budgets  and  rein  in  officers."  On 
Monday,  Mayor  Bill  de  Blasio  "announced  that  the  city  was  sending  more  officers  into  the  streets  and  declared  he  would  not 
retreat  from  efforts  to  overhaul  the  Police  Department." 

Federal,  Local  Authorities  Arrest  14  Suspects  In  South  Carolina  Car-Jacking,  Drug  Ring 

The  Columbia  TSC)  State  I  (6/23,  Monk)  reports,  "More  than  200  federal  and  local  law  enforcement  officers  on  Tuesday 

rounded  up  14  members  of  an  alleged  Columbia-area  violent  gang  whose  members  specialized  in  carjackings,  armed  robberies 
and  drug  dealing."  According  to  US  Attorney  Peter  McCoy,  who  announced  the  arrests  Tuesday,  the  arrests  "were  the  result  of 
a  nearly  two-year  investigation  by  the  FBI,  the  DEA  and  local  law  enforcement  into  a  spike  in  gang-related  violence  in  Richland, 
Lexington  and  Kershaw  counties  that  began  in  July  2018."  FBI  South  Carolina  SAC  Jody  Norris  said,  "Even  in  the  midst  of  a 
pandemic,  the  FBI  and  its  task  forces  will  continue  to  find  and  arrest  drug  traffickers  who  work  against  the  people  of  South 
Carolina."  Also  reporting  are  WACH-TV  IHIcolumbia,  SC  (6/23,  Lanahan)  and  WIS-TV  Bicolumbia,  SC  (6/23,  Greene). 

GLOBAL  SECURITY 


Suicide  Bomber  Targets  Turkish  Military  Base  In  Somalia 

The  New  York  Times  (6/23,  Mohamed,  Dahir)  reports,  "Two  people  were  killed  after  a  suicide  bomber  detonated  his 
explosives  outside  Turkey's  largest  overseas  military  base  in  Mogadishu  on  Tuesday."  The  attack,  which  the  Times  says  "bears 
the  hallmarks  of  the  Shabab  terrorist  group,  was  carried  out  just  before  9  a.m.  as  recruits  lined  up  for  enlistment  at  Camp 
Turksom,  where  hundreds  of  Somali  soldiers  are  trained  and  the  new  enrollment  of  dozens  was  underway." 

The  AP  (6/23,  Guled)  says  Tuesday's  attack  marks  "the  first  time  Turkey's  largest  overseas  military  base  has  been 
attacked  by  the  al-Qaida-linked  al-Shabab  extremist  group,"  which  "quickly  claimed  responsibility,  according  to  its  Radio  al- 
Furqan  affiliate." 

Secret  Recordings  Detail  Neo-Nazi  Group's  Grooming,  Recruiting  Process 

Fox  News  (6/23,  Chakraborty)  reports  on  newly  revealed  secret  recordings,  first  reported  by  the  BBC,  which  show  "senior 
members  of  The  Base,  a  hate  group  started  in  the  United  States,  interviewing  young  applicants,  discussing  their  prospects  and 
ways  to  radicalize  them."  The  founder  of  the  group,  American  Rinaldo  Nazzaro,  "who  now  directs  members  of  his  group  from 
St.  Petersburg,  Russia,  is  heard  asking  prospective  members  about  their  ethnicity,  radicalization  journey  and  their  experience 
with  weapons."  Fox  reports  Nazzaro  "purportedly  worked  as  an  analyst  for  the  FBI  and  as  a  contractor  for  the  Pentagon  before 
he  left  New  York  for  Russia  less  than  two  years  ago." 

ALSO  IN  THE  NEWS 

FCC  To  Vote  Next  Month  On  Making  "988"  New  Suicide  Hotline  Number 

The  AP  (6/23,  Arbel)  reports  the  FCC  "will  vote  in  July  on  whether  to  make  '988'  the  number  to  reach  a  suicide  prevention 
hotline."  The  Commission  explained  that  "phone  service  providers  will  have  until  July  2022  to  implement  the  new  number,  if 
the  measure  is  approved  in  July,  as  expected." 
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POLICING  &  POLICY 


Top  Senate  Democrats  Dismiss  Republican  Policing 
Reform  Bill 

The  AP  (6/23,  Mascaro)  reports  Congress  is  "hitting  an  impasse  on 
aolicing  legislation,  as  key  Senate  Democrats  on  Tuesday  opposed  a 
Republican  proposal  as  inadequate,  leaving  the  parties  to  decide 
whether  to  take  on  the  hard  job  of  negotiating  a  compromise  or  walk 
away."  Ahead  of  a  test  vote  Wednesday,  Senate  Majority  Leader 
McConnell  "acknowledged  it  may  fall  short,"  and  the  GOP  bill's  author, 
sen.  Tim  Scott  (R-SC),  "warned  against  a  partisan,  political  debate  that 
chisels  away  confidence  in  the  nation's  institutions."  Reuters 
[6/23,  Morgan)  similarly  says  "Democrats  and  Republicans.. .found 
themselves  in  a  partisan  deadlock  on  Tuesday." 

AP-NORC  Poll:  Nearly  All  Americans  Back  Some  Kind  Of 
Criminal  Justice  Reform.  The  AP  I  B(6/23,  Long,  Fingerhut)  reports  that  Americans  "overwhelmingly  want  clear  standards 
on  when  police  officers  may  use  force  and  consequences  for  officers  who  do  so  excessively,  according  to  a  new  poll  that  finds 
nearly  all  Americans  favor  at  least  some  level  of  change  to  the  nation's  criminal  justice  system."  The  new  AP-NORC  poll  "also 
finds  there  is  strong  support  for  penalizing  officers  who  engage  in  racially  biased  policing." 

Confronting  Nazi  Legacy  Part  Of  German  Police  Training 

The  New  York  Times  (6/23,  Bennhold,  Eddy)  reports  that  "visiting  a  former  concentration  camp  is  mandatory  for  every 


future  police  officer  in  Berlin."  To  the  Times,  it  is  "one  of  the  ways  in  which  policing  was  fundamentally  overhauled  in  Germany 
afterWorld  Warll." 

Rhode  Island  Governor  Signs  Ban  On  3D-Printed  Weapons,  "Ghost  Guns" 

The  AP  (6/23,  Pratt)  reports  that  Rhode  Island  Gov.  Gina  Raimondo  "on  Tuesday  signed  into  law  bills  that  ban  3D-printed 
guns  and  so-called  'ghost  guns'  in  the  state."  The  bills  "are  'a  matter  of  public  health,'  she  said."  The  bills  "were  approved  by 
the  legislature  last  week,"  and  "make  it  illegal  to  manufacture,  import,  sell,  ship,  deliver,  possess,  transfer  or  receive  any  such 
firearms.  Anyone  who  violates  the  ban  and  is  convicted  could  serve  up  to  10  years  in  prison  and  faces  fines  of  up  $10,000.  The 
laws  take  effect  in  30  days." 

Seattle,  Washington  To  End  Anti-Loitering  Law 

Fox  News  (6/23,  Carter)  reports,  "Seattle  is  moving  to  end  a  longstanding  city  law  that  allowed  police  to  arrest  someone 
for  loitering,  if  they  are  also  suspected  of  being  a  possible  drug  offender  or  sex  worker."  According  to  Fox  News,  "The  twin  bills, 
passed  unanimously  by  the  Seattle  City  Council  Monday,  effectively  block  authorities  from  arresting  someone  for  loitering  in 
relation  to  a  drug  or  a  prostitution  inquiry.  Both  laws,  according  to  the  Chicago-Kent  Law  Review,  have  historically  targeted 
people  of  color." 

Georgia  Lawmakers  Pass  Bills  On  Hate  Crimes,  Enhanced  Police  Protections 

The  AP  (6/23,  Nadler,  Amy)  reports,  "Georgia's  legislature  on  Tuesday  passed  hate  crimes  legislation  deemed  essential  by 
business  and  many  political  leaders,  sending  the  measure  to  Gov.  Brian  Kemp's  desk.  The  price  Republicans  exacted  for  moving 
that  legislation  forward  was  simultaneous  passage  of  a  separate  bill  that  would  mandate  penalties  for  crimes  targeting  police 
and  other  first  responders."  According  to  the  AP,  "The  action  comes  after  Senate  Republicans  had  added  police  as  a  protected 
class  to  the  hate  crimes  legislation  last  week  in  committee,  but  then  later  moved  those  protections  to  a  separate  bill  in  a  deal 
between  the  parties.  Democrats  on  Tuesday  voted  overwhelmingly  against  House  Bill  838,  which  includes  the  increased 
protections  for  first  responders.  The  hate  crimes  legislation,  House  Bill  426,  had  bipartisan  support." 


The  impact  of  an  officer's  line-of-duty  injury  may  continue  beyond  the  initial  event  and  hospitalization.  Agencies 
can  prepare  to  provide  resources  such  as  behavioral  health  and  wellness  or  peer  support  services  to  officers  and 
their  families.  The  Line-of-Duty  Serious  Injury  Considerations  document  and  Concepts  &  Issues  paper  from  the 
IACP  Law  Enforcement  Policy  Center  provides  guidelines  for  agencies  to  consider. 

Review  documents  and  resources. 


Connect  with  the  IACP 
online: 


IACP  Event  Calendar: 
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Law  Enforcement  Concerned  About  Rash  Of  Gun-Store  Robberies 

Politico  (6/23,  Swan)  reports,  "A  rash  of  gun-store  burglaries  has  alarmed  law  enforcement  officials,  and  comes  amid 
widespread  protests  that  have  been  accompanied  by  incidents  of  looting  and  vandalism  across  the  country."  According  to 
Politico,  "In  the  last  days  of  May  and  first  week  of  June,  there  were  more  than  90  attempted  or  successful  burglaries  of  gun 
stores,  according  to  the  Bureau  of  Alcohol,  Tobacco,  and  Firearms  (ATF).  More  than  1,000  guns  were  stolen  in  that  window  of 
time,  the  bureau's  assistant  director  of  field  operations  Tom  Chittum  told  POLITICO.  'It's  a  lot  of  guns,'  Chittum  said  in  an 
interview.  'It's  the  biggest  spike  I  have  ever  seen  of  gun  store  burglaries.'"  Chittum  "said  investigations  into  the  surge  of  gun 
store  burglaries  are  underway,  and  that  some  of  the  burglaries  appeared  to  be  part  of  broader  looting.  Other  cases,  he  added, 
may  have  been  the  work  of  opportunists." 


Gun  Violence  Spikes  In  New  York  City 

The  New  York  Times  (6/23,  Southall,  Macfarquhar)  reports,  "It  has  been  nearly  a  quarter  century  since  New  York  City 
experienced  as  much  gun  violence  in  the  month  of  June  as  it  has  seen  this  year."  The  city  "logged  125  shootings  in  the  first 
three  weeks  of  the  month,  more  than  double  the  number  recorded  over  in  same  period  last  year,  police  data  show.  Gunmen 
opened  fire  during  house  parties,  barbecues,  dice  games,  and  carried  out  coldly  calculated  street  executions."  New  York  "is  not 
alone.  Shootings  are  on  the  rise  in  other  big  cities  across  the  country,  including  Chicago  and  Minneapolis,  a  trend  that  some 
conservatives  have  seized  on  to  argue  against  the  recent  demands  of  protesters  to  cut  police  budgets  and  rein  in  officers."  On 
Monday,  Mayor  Bill  de  Blasio  "announced  that  the  city  was  sending  more  officers  into  the  streets  and  declared  he  would  not 
retreat  from  efforts  to  overhaul  the  Police  Department." 

Federal,  Local  Authorities  Arrest  14  Suspects  In  South  Carolina  Car-Jacking,  Drug  Ring 

The  Columbia  TSC)  State  I  (6/23,  Monk)  reports,  "More  than  200  federal  and  local  law  enforcement  officers  on  Tuesday 

rounded  up  14  members  of  an  alleged  Columbia-area  violent  gang  whose  members  specialized  in  carjackings,  armed  robberies 
and  drug  dealing."  According  to  US  Attorney  Peter  McCoy,  who  announced  the  arrests  Tuesday,  the  arrests  "were  the  result  of 
a  nearly  two-year  investigation  by  the  FBI,  the  DEA  and  local  law  enforcement  into  a  spike  in  gang-related  violence  in  Richland, 
Lexington  and  Kershaw  counties  that  began  in  July  2018."  FBI  South  Carolina  SAC  Jody  Norris  said,  "Even  in  the  midst  of  a 
pandemic,  the  FBI  and  its  task  forces  will  continue  to  find  and  arrest  drug  traffickers  who  work  against  the  people  of  South 
Carolina."  Also  reporting  are  WACH-TV  IHIcolumbia,  SC  (6/23,  Lanahan)  and  WIS-TV  Bicolumbia,  SC  (6/23,  Greene). 

GLOBAL  SECURITY 


Suicide  Bomber  Targets  Turkish  Military  Base  In  Somalia 

The  New  York  Times  (6/23,  Mohamed,  Dahir)  reports,  "Two  people  were  killed  after  a  suicide  bomber  detonated  his 
explosives  outside  Turkey's  largest  overseas  military  base  in  Mogadishu  on  Tuesday."  The  attack,  which  the  Times  says  "bears 
the  hallmarks  of  the  Shabab  terrorist  group,  was  carried  out  just  before  9  a.m.  as  recruits  lined  up  for  enlistment  at  Camp 
Turksom,  where  hundreds  of  Somali  soldiers  are  trained  and  the  new  enrollment  of  dozens  was  underway." 

The  AP  (6/23,  Guled)  says  Tuesday's  attack  marks  "the  first  time  Turkey's  largest  overseas  military  base  has  been 
attacked  by  the  al-Qaida-linked  al-Shabab  extremist  group,"  which  "quickly  claimed  responsibility,  according  to  its  Radio  al- 
Furqan  affiliate." 

Secret  Recordings  Detail  Neo-Nazi  Group's  Grooming,  Recruiting  Process 

Fox  News  (6/23,  Chakraborty)  reports  on  newly  revealed  secret  recordings,  first  reported  by  the  BBC,  which  show  "senior 
members  of  The  Base,  a  hate  group  started  in  the  United  States,  interviewing  young  applicants,  discussing  their  prospects  and 
ways  to  radicalize  them."  The  founder  of  the  group,  American  Rinaldo  Nazzaro,  "who  now  directs  members  of  his  group  from 
St.  Petersburg,  Russia,  is  heard  asking  prospective  members  about  their  ethnicity,  radicalization  journey  and  their  experience 
with  weapons."  Fox  reports  Nazzaro  "purportedly  worked  as  an  analyst  for  the  FBI  and  as  a  contractor  for  the  Pentagon  before 
he  left  New  York  for  Russia  less  than  two  years  ago." 

ALSO  IN  THE  NEWS 

FCC  To  Vote  Next  Month  On  Making  "988"  New  Suicide  Hotline  Number 

The  AP  (6/23,  Arbel)  reports  the  FCC  "will  vote  in  July  on  whether  to  make  '988'  the  number  to  reach  a  suicide  prevention 
hotline."  The  Commission  explained  that  "phone  service  providers  will  have  until  July  2022  to  implement  the  new  number,  if 
the  measure  is  approved  in  July,  as  expected." 
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•  US  Supreme  Court  Will  Not  Revisit  Challenge  To  Qualified  Immunity  For  Police 

•  Swedish  Rape  Conviction  Rates  Rise  75%  After  Change  In  Law 

•  "Blueleaks"  Hackers  Release  "Hundreds  Of  Thousands"  Of  Private  Records  On  Officers 
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POLICING  &  POLICY 


Top  Senate  Democrats  Dismiss  Republican  Policing 
Reform  Bill 

The  AP  (6/23,  Mascaro)  reports  Congress  is  "hitting  an  impasse  on 
aolicing  legislation,  as  key  Senate  Democrats  on  Tuesday  opposed  a 
Republican  proposal  as  inadequate,  leaving  the  parties  to  decide 
whether  to  take  on  the  hard  job  of  negotiating  a  compromise  or  walk 
away."  Ahead  of  a  test  vote  Wednesday,  Senate  Majority  Leader 
McConnell  "acknowledged  it  may  fall  short,"  and  the  GOP  bill's  author, 
sen.  Tim  Scott  (R-SC),  "warned  against  a  partisan,  political  debate  that 
chisels  away  confidence  in  the  nation's  institutions."  Reuters 
[6/23,  Morgan)  similarly  says  "Democrats  and  Republicans.. .found 
themselves  in  a  partisan  deadlock  on  Tuesday." 

AP-NORC  Poll:  Nearly  All  Americans  Back  Some  Kind  Of 
Criminal  Justice  Reform.  The  AP  I  B(6/23,  Long,  Fingerhut)  reports  that  Americans  "overwhelmingly  want  clear  standards 
on  when  police  officers  may  use  force  and  consequences  for  officers  who  do  so  excessively,  according  to  a  new  poll  that  finds 
nearly  all  Americans  favor  at  least  some  level  of  change  to  the  nation's  criminal  justice  system."  The  new  AP-NORC  poll  "also 
finds  there  is  strong  support  for  penalizing  officers  who  engage  in  racially  biased  policing." 

Confronting  Nazi  Legacy  Part  Of  German  Police  Training 

The  New  York  Times  (6/23,  Bennhold,  Eddy)  reports  that  "visiting  a  former  concentration  camp  is  mandatory  for  every 


future  police  officer  in  Berlin."  To  the  Times,  it  is  "one  of  the  ways  in  which  policing  was  fundamentally  overhauled  in  Germany 
afterWorld  Warll." 

Rhode  Island  Governor  Signs  Ban  On  3D-Printed  Weapons,  "Ghost  Guns" 

The  AP  (6/23,  Pratt)  reports  that  Rhode  Island  Gov.  Gina  Raimondo  "on  Tuesday  signed  into  law  bills  that  ban  3D-printed 
guns  and  so-called  'ghost  guns'  in  the  state."  The  bills  "are  'a  matter  of  public  health,'  she  said."  The  bills  "were  approved  by 
the  legislature  last  week,"  and  "make  it  illegal  to  manufacture,  import,  sell,  ship,  deliver,  possess,  transfer  or  receive  any  such 
firearms.  Anyone  who  violates  the  ban  and  is  convicted  could  serve  up  to  10  years  in  prison  and  faces  fines  of  up  $10,000.  The 
laws  take  effect  in  30  days." 

Seattle,  Washington  To  End  Anti-Loitering  Law 

Fox  News  (6/23,  Carter)  reports,  "Seattle  is  moving  to  end  a  longstanding  city  law  that  allowed  police  to  arrest  someone 
for  loitering,  if  they  are  also  suspected  of  being  a  possible  drug  offender  or  sex  worker."  According  to  Fox  News,  "The  twin  bills, 
passed  unanimously  by  the  Seattle  City  Council  Monday,  effectively  block  authorities  from  arresting  someone  for  loitering  in 
relation  to  a  drug  or  a  prostitution  inquiry.  Both  laws,  according  to  the  Chicago-Kent  Law  Review,  have  historically  targeted 
people  of  color." 

Georgia  Lawmakers  Pass  Bills  On  Hate  Crimes,  Enhanced  Police  Protections 

The  AP  (6/23,  Nadler,  Amy)  reports,  "Georgia's  legislature  on  Tuesday  passed  hate  crimes  legislation  deemed  essential  by 
business  and  many  political  leaders,  sending  the  measure  to  Gov.  Brian  Kemp's  desk.  The  price  Republicans  exacted  for  moving 
that  legislation  forward  was  simultaneous  passage  of  a  separate  bill  that  would  mandate  penalties  for  crimes  targeting  police 
and  other  first  responders."  According  to  the  AP,  "The  action  comes  after  Senate  Republicans  had  added  police  as  a  protected 
class  to  the  hate  crimes  legislation  last  week  in  committee,  but  then  later  moved  those  protections  to  a  separate  bill  in  a  deal 
between  the  parties.  Democrats  on  Tuesday  voted  overwhelmingly  against  House  Bill  838,  which  includes  the  increased 
protections  for  first  responders.  The  hate  crimes  legislation,  House  Bill  426,  had  bipartisan  support." 


The  impact  of  an  officer's  line-of-duty  injury  may  continue  beyond  the  initial  event  and  hospitalization.  Agencies 
can  prepare  to  provide  resources  such  as  behavioral  health  and  wellness  or  peer  support  services  to  officers  and 
their  families.  The  Line-of-Duty  Serious  Injury  Considerations  document  and  Concepts  &  Issues  paper  from  the 
IACP  Law  Enforcement  Policy  Center  provides  guidelines  for  agencies  to  consider. 
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CRIME  &  DRUGS 


Law  Enforcement  Concerned  About  Rash  Of  Gun-Store  Robberies 

Politico  (6/23,  Swan)  reports,  "A  rash  of  gun-store  burglaries  has  alarmed  law  enforcement  officials,  and  comes  amid 
widespread  protests  that  have  been  accompanied  by  incidents  of  looting  and  vandalism  across  the  country."  According  to 
Politico,  "In  the  last  days  of  May  and  first  week  of  June,  there  were  more  than  90  attempted  or  successful  burglaries  of  gun 
stores,  according  to  the  Bureau  of  Alcohol,  Tobacco,  and  Firearms  (ATF).  More  than  1,000  guns  were  stolen  in  that  window  of 
time,  the  bureau's  assistant  director  of  field  operations  Tom  Chittum  told  POLITICO.  'It's  a  lot  of  guns,'  Chittum  said  in  an 
interview.  'It's  the  biggest  spike  I  have  ever  seen  of  gun  store  burglaries.'"  Chittum  "said  investigations  into  the  surge  of  gun 
store  burglaries  are  underway,  and  that  some  of  the  burglaries  appeared  to  be  part  of  broader  looting.  Other  cases,  he  added, 
may  have  been  the  work  of  opportunists." 


Gun  Violence  Spikes  In  New  York  City 

The  New  York  Times  (6/23,  Southall,  Macfarquhar)  reports,  "It  has  been  nearly  a  quarter  century  since  New  York  City 
experienced  as  much  gun  violence  in  the  month  of  June  as  it  has  seen  this  year."  The  city  "logged  125  shootings  in  the  first 
three  weeks  of  the  month,  more  than  double  the  number  recorded  over  in  same  period  last  year,  police  data  show.  Gunmen 
opened  fire  during  house  parties,  barbecues,  dice  games,  and  carried  out  coldly  calculated  street  executions."  New  York  "is  not 
alone.  Shootings  are  on  the  rise  in  other  big  cities  across  the  country,  including  Chicago  and  Minneapolis,  a  trend  that  some 
conservatives  have  seized  on  to  argue  against  the  recent  demands  of  protesters  to  cut  police  budgets  and  rein  in  officers."  On 
Monday,  Mayor  Bill  de  Blasio  "announced  that  the  city  was  sending  more  officers  into  the  streets  and  declared  he  would  not 
retreat  from  efforts  to  overhaul  the  Police  Department." 

Federal,  Local  Authorities  Arrest  14  Suspects  In  South  Carolina  Car-Jacking,  Drug  Ring 

The  Columbia  TSC)  State  I  (6/23,  Monk)  reports,  "More  than  200  federal  and  local  law  enforcement  officers  on  Tuesday 

rounded  up  14  members  of  an  alleged  Columbia-area  violent  gang  whose  members  specialized  in  carjackings,  armed  robberies 
and  drug  dealing."  According  to  US  Attorney  Peter  McCoy,  who  announced  the  arrests  Tuesday,  the  arrests  "were  the  result  of 
a  nearly  two-year  investigation  by  the  FBI,  the  DEA  and  local  law  enforcement  into  a  spike  in  gang-related  violence  in  Richland, 
Lexington  and  Kershaw  counties  that  began  in  July  2018."  FBI  South  Carolina  SAC  Jody  Norris  said,  "Even  in  the  midst  of  a 
pandemic,  the  FBI  and  its  task  forces  will  continue  to  find  and  arrest  drug  traffickers  who  work  against  the  people  of  South 
Carolina."  Also  reporting  are  WACH-TV  IHIcolumbia,  SC  (6/23,  Lanahan)  and  WIS-TV  Bicolumbia,  SC  (6/23,  Greene). 

GLOBAL  SECURITY 


Suicide  Bomber  Targets  Turkish  Military  Base  In  Somalia 

The  New  York  Times  (6/23,  Mohamed,  Dahir)  reports,  "Two  people  were  killed  after  a  suicide  bomber  detonated  his 
explosives  outside  Turkey's  largest  overseas  military  base  in  Mogadishu  on  Tuesday."  The  attack,  which  the  Times  says  "bears 
the  hallmarks  of  the  Shabab  terrorist  group,  was  carried  out  just  before  9  a.m.  as  recruits  lined  up  for  enlistment  at  Camp 
Turksom,  where  hundreds  of  Somali  soldiers  are  trained  and  the  new  enrollment  of  dozens  was  underway." 

The  AP  (6/23,  Guled)  says  Tuesday's  attack  marks  "the  first  time  Turkey's  largest  overseas  military  base  has  been 
attacked  by  the  al-Qaida-linked  al-Shabab  extremist  group,"  which  "quickly  claimed  responsibility,  according  to  its  Radio  al- 
Furqan  affiliate." 

Secret  Recordings  Detail  Neo-Nazi  Group's  Grooming,  Recruiting  Process 

Fox  News  (6/23,  Chakraborty)  reports  on  newly  revealed  secret  recordings,  first  reported  by  the  BBC,  which  show  "senior 
members  of  The  Base,  a  hate  group  started  in  the  United  States,  interviewing  young  applicants,  discussing  their  prospects  and 
ways  to  radicalize  them."  The  founder  of  the  group,  American  Rinaldo  Nazzaro,  "who  now  directs  members  of  his  group  from 
St.  Petersburg,  Russia,  is  heard  asking  prospective  members  about  their  ethnicity,  radicalization  journey  and  their  experience 
with  weapons."  Fox  reports  Nazzaro  "purportedly  worked  as  an  analyst  for  the  FBI  and  as  a  contractor  for  the  Pentagon  before 
he  left  New  York  for  Russia  less  than  two  years  ago." 

ALSO  IN  THE  NEWS 

FCC  To  Vote  Next  Month  On  Making  "988"  New  Suicide  Hotline  Number 

The  AP  (6/23,  Arbel)  reports  the  FCC  "will  vote  in  July  on  whether  to  make  '988'  the  number  to  reach  a  suicide  prevention 
hotline."  The  Commission  explained  that  "phone  service  providers  will  have  until  July  2022  to  implement  the  new  number,  if 
the  measure  is  approved  in  July,  as  expected." 
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NYTimes  Analysis:  Antifa  Rumors  Show  Ways  Information  Spreads  Locally 


Subscriber  Tools 

•  Change  Email  Address 

•  Send  Feedback 

•  Unsubscribe 

•  Email  Help 

•  Archives 

The  Lead  is  a  daily  news  briefing  selected  from  thousands  of  sources  by  the  editors  of  Bulletin  Media.  Neither  Bulletin  Media  nor  the 
International  Association  of  Chiefs  of  Police  is  liable  for  the  use  of  or  reliance  on  any  information  contained  in  this  briefing.  The  presence  of 
articles  and/or  advertising  does  not  endorse,  nor  imply  endorsement  of,  any  products  or  services  by  the  IACP. 

This  complimentary  copy  of  The  Lead  was  sent  to  keith. morrison@cookcountyil.gov  as  a  member  benefit.  To  see  how  we  protect  our  data,  or  for 
any  questions  on  data  access,  view  Bulletin  Media's  privacy  policy. 

For  information  about  other  member  benefits,  please  contact  the  IACP  at  membership@theiacp.org  or  1.800.THE  IACP. 

International  Association  of  Chiefs  of  Police  |  44  Canal  Center  Plaza  Suite  200  |  Alexandria,  VA  22314 
Copyright  ©  2020  by  Bulletin  Media  |  11190  Sunrise  Valley  Drive  Suite  20  |  Reston,  VA  20191 


lACP's  The  Lead:  Top  Senate  Democrats  Dismiss  Republican  Policing  Reform 
Bill. 


From:  The  IACP  <TheLead@iacp. bulletinmedia.com> 

To:  noureen.kapadia@cookcountyil.gov,  Noureen  Kapadia  (Sheriff) 

<Noureen.Kapadia@cookcountyil.gov> 

Sent:  June  24,  2020  6:25:01  AM  CDT 

Received:  June  24,  2020  6:25:07  AM  CDT 


External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 

If  you  are  unable  to  see  the  message  or  images  below,  click  here  to  view 


POLICING  &  POLICY 


Top  Senate  Democrats  Dismiss  Republican  Policing 
Reform  Bill 

The  AP  (6/23,  Mascaro)  reports  Congress  is  "hitting  an  impasse  on 
aolicing  legislation,  as  key  Senate  Democrats  on  Tuesday  opposed  a 
Republican  proposal  as  inadequate,  leaving  the  parties  to  decide 
whether  to  take  on  the  hard  job  of  negotiating  a  compromise  or  walk 
away."  Ahead  of  a  test  vote  Wednesday,  Senate  Majority  Leader 
McConnell  "acknowledged  it  may  fall  short,"  and  the  GOP  bill's  author, 
sen.  Tim  Scott  (R-SC),  "warned  against  a  partisan,  political  debate  that 
chisels  away  confidence  in  the  nation's  institutions."  Reuters 
[6/23,  Morgan)  similarly  says  "Democrats  and  Republicans.. .found 
themselves  in  a  partisan  deadlock  on  Tuesday." 

AP-NORC  Poll:  Nearly  All  Americans  Back  Some  Kind  Of 
Criminal  Justice  Reform.  The  AP  I  B(6/23,  Long,  Fingerhut)  reports  that  Americans  "overwhelmingly  want  clear  standards 
on  when  police  officers  may  use  force  and  consequences  for  officers  who  do  so  excessively,  according  to  a  new  poll  that  finds 
nearly  all  Americans  favor  at  least  some  level  of  change  to  the  nation's  criminal  justice  system."  The  new  AP-NORC  poll  "also 
finds  there  is  strong  support  for  penalizing  officers  who  engage  in  racially  biased  policing." 

Confronting  Nazi  Legacy  Part  Of  German  Police  Training 

The  New  York  Times  (6/23,  Bennhold,  Eddy)  reports  that  "visiting  a  former  concentration  camp  is  mandatory  for  every 


future  police  officer  in  Berlin."  To  the  Times,  it  is  "one  of  the  ways  in  which  policing  was  fundamentally  overhauled  in  Germany 
afterWorld  Warll." 

Rhode  Island  Governor  Signs  Ban  On  3D-Printed  Weapons,  "Ghost  Guns" 

The  AP  (6/23,  Pratt)  reports  that  Rhode  Island  Gov.  Gina  Raimondo  "on  Tuesday  signed  into  law  bills  that  ban  3D-printed 
guns  and  so-called  'ghost  guns'  in  the  state."  The  bills  "are  'a  matter  of  public  health,'  she  said."  The  bills  "were  approved  by 
the  legislature  last  week,"  and  "make  it  illegal  to  manufacture,  import,  sell,  ship,  deliver,  possess,  transfer  or  receive  any  such 
firearms.  Anyone  who  violates  the  ban  and  is  convicted  could  serve  up  to  10  years  in  prison  and  faces  fines  of  up  $10,000.  The 
laws  take  effect  in  30  days." 

Seattle,  Washington  To  End  Anti-Loitering  Law 

Fox  News  (6/23,  Carter)  reports,  "Seattle  is  moving  to  end  a  longstanding  city  law  that  allowed  police  to  arrest  someone 
for  loitering,  if  they  are  also  suspected  of  being  a  possible  drug  offender  or  sex  worker."  According  to  Fox  News,  "The  twin  bills, 
passed  unanimously  by  the  Seattle  City  Council  Monday,  effectively  block  authorities  from  arresting  someone  for  loitering  in 
relation  to  a  drug  or  a  prostitution  inquiry.  Both  laws,  according  to  the  Chicago-Kent  Law  Review,  have  historically  targeted 
people  of  color." 

Georgia  Lawmakers  Pass  Bills  On  Hate  Crimes,  Enhanced  Police  Protections 

The  AP  (6/23,  Nadler,  Amy)  reports,  "Georgia's  legislature  on  Tuesday  passed  hate  crimes  legislation  deemed  essential  by 
business  and  many  political  leaders,  sending  the  measure  to  Gov.  Brian  Kemp's  desk.  The  price  Republicans  exacted  for  moving 
that  legislation  forward  was  simultaneous  passage  of  a  separate  bill  that  would  mandate  penalties  for  crimes  targeting  police 
and  other  first  responders."  According  to  the  AP,  "The  action  comes  after  Senate  Republicans  had  added  police  as  a  protected 
class  to  the  hate  crimes  legislation  last  week  in  committee,  but  then  later  moved  those  protections  to  a  separate  bill  in  a  deal 
between  the  parties.  Democrats  on  Tuesday  voted  overwhelmingly  against  House  Bill  838,  which  includes  the  increased 
protections  for  first  responders.  The  hate  crimes  legislation,  House  Bill  426,  had  bipartisan  support." 
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Law  Enforcement  Concerned  About  Rash  Of  Gun-Store  Robberies 

Politico  (6/23,  Swan)  reports,  "A  rash  of  gun-store  burglaries  has  alarmed  law  enforcement  officials,  and  comes  amid 
widespread  protests  that  have  been  accompanied  by  incidents  of  looting  and  vandalism  across  the  country."  According  to 
Politico,  "In  the  last  days  of  May  and  first  week  of  June,  there  were  more  than  90  attempted  or  successful  burglaries  of  gun 
stores,  according  to  the  Bureau  of  Alcohol,  Tobacco,  and  Firearms  (ATF).  More  than  1,000  guns  were  stolen  in  that  window  of 
time,  the  bureau's  assistant  director  of  field  operations  Tom  Chittum  told  POLITICO.  'It's  a  lot  of  guns,'  Chittum  said  in  an 
interview.  'It's  the  biggest  spike  I  have  ever  seen  of  gun  store  burglaries.'"  Chittum  "said  investigations  into  the  surge  of  gun 
store  burglaries  are  underway,  and  that  some  of  the  burglaries  appeared  to  be  part  of  broader  looting.  Other  cases,  he  added, 
may  have  been  the  work  of  opportunists." 


Gun  Violence  Spikes  In  New  York  City 

The  New  York  Times  (6/23,  Southall,  Macfarquhar)  reports,  "It  has  been  nearly  a  quarter  century  since  New  York  City 
experienced  as  much  gun  violence  in  the  month  of  June  as  it  has  seen  this  year."  The  city  "logged  125  shootings  in  the  first 
three  weeks  of  the  month,  more  than  double  the  number  recorded  over  in  same  period  last  year,  police  data  show.  Gunmen 
opened  fire  during  house  parties,  barbecues,  dice  games,  and  carried  out  coldly  calculated  street  executions."  New  York  "is  not 
alone.  Shootings  are  on  the  rise  in  other  big  cities  across  the  country,  including  Chicago  and  Minneapolis,  a  trend  that  some 
conservatives  have  seized  on  to  argue  against  the  recent  demands  of  protesters  to  cut  police  budgets  and  rein  in  officers."  On 
Monday,  Mayor  Bill  de  Blasio  "announced  that  the  city  was  sending  more  officers  into  the  streets  and  declared  he  would  not 
retreat  from  efforts  to  overhaul  the  Police  Department." 

Federal,  Local  Authorities  Arrest  14  Suspects  In  South  Carolina  Car-Jacking,  Drug  Ring 

The  Columbia  TSC)  State  I  (6/23,  Monk)  reports,  "More  than  200  federal  and  local  law  enforcement  officers  on  Tuesday 

rounded  up  14  members  of  an  alleged  Columbia-area  violent  gang  whose  members  specialized  in  carjackings,  armed  robberies 
and  drug  dealing."  According  to  US  Attorney  Peter  McCoy,  who  announced  the  arrests  Tuesday,  the  arrests  "were  the  result  of 
a  nearly  two-year  investigation  by  the  FBI,  the  DEA  and  local  law  enforcement  into  a  spike  in  gang-related  violence  in  Richland, 
Lexington  and  Kershaw  counties  that  began  in  July  2018."  FBI  South  Carolina  SAC  Jody  Norris  said,  "Even  in  the  midst  of  a 
pandemic,  the  FBI  and  its  task  forces  will  continue  to  find  and  arrest  drug  traffickers  who  work  against  the  people  of  South 
Carolina."  Also  reporting  are  WACH-TV  IHIcolumbia,  SC  (6/23,  Lanahan)  and  WIS-TV  Bicolumbia,  SC  (6/23,  Greene). 

GLOBAL  SECURITY 


Suicide  Bomber  Targets  Turkish  Military  Base  In  Somalia 

The  New  York  Times  (6/23,  Mohamed,  Dahir)  reports,  "Two  people  were  killed  after  a  suicide  bomber  detonated  his 
explosives  outside  Turkey's  largest  overseas  military  base  in  Mogadishu  on  Tuesday."  The  attack,  which  the  Times  says  "bears 
the  hallmarks  of  the  Shabab  terrorist  group,  was  carried  out  just  before  9  a.m.  as  recruits  lined  up  for  enlistment  at  Camp 
Turksom,  where  hundreds  of  Somali  soldiers  are  trained  and  the  new  enrollment  of  dozens  was  underway." 

The  AP  (6/23,  Guled)  says  Tuesday's  attack  marks  "the  first  time  Turkey's  largest  overseas  military  base  has  been 
attacked  by  the  al-Qaida-linked  al-Shabab  extremist  group,"  which  "quickly  claimed  responsibility,  according  to  its  Radio  al- 
Furqan  affiliate." 

Secret  Recordings  Detail  Neo-Nazi  Group's  Grooming,  Recruiting  Process 

Fox  News  (6/23,  Chakraborty)  reports  on  newly  revealed  secret  recordings,  first  reported  by  the  BBC,  which  show  "senior 
members  of  The  Base,  a  hate  group  started  in  the  United  States,  interviewing  young  applicants,  discussing  their  prospects  and 
ways  to  radicalize  them."  The  founder  of  the  group,  American  Rinaldo  Nazzaro,  "who  now  directs  members  of  his  group  from 
St.  Petersburg,  Russia,  is  heard  asking  prospective  members  about  their  ethnicity,  radicalization  journey  and  their  experience 
with  weapons."  Fox  reports  Nazzaro  "purportedly  worked  as  an  analyst  for  the  FBI  and  as  a  contractor  for  the  Pentagon  before 
he  left  New  York  for  Russia  less  than  two  years  ago." 

ALSO  IN  THE  NEWS 

FCC  To  Vote  Next  Month  On  Making  "988"  New  Suicide  Hotline  Number 

The  AP  (6/23,  Arbel)  reports  the  FCC  "will  vote  in  July  on  whether  to  make  '988'  the  number  to  reach  a  suicide  prevention 
hotline."  The  Commission  explained  that  "phone  service  providers  will  have  until  July  2022  to  implement  the  new  number,  if 
the  measure  is  approved  in  July,  as  expected." 
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•  "Blueleaks"  Hackers  Release  "Hundreds  Of  Thousands"  Of  Private  Records  On  Officers 
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POLICING  &  POLICY 


Top  Senate  Democrats  Dismiss  Republican  Policing 
Reform  Bill 

The  AP  (6/23,  Mascaro)  reports  Congress  is  "hitting  an  impasse  on 
aolicing  legislation,  as  key  Senate  Democrats  on  Tuesday  opposed  a 
Republican  proposal  as  inadequate,  leaving  the  parties  to  decide 
whether  to  take  on  the  hard  job  of  negotiating  a  compromise  or  walk 
away."  Ahead  of  a  test  vote  Wednesday,  Senate  Majority  Leader 
McConnell  "acknowledged  it  may  fall  short,"  and  the  GOP  bill's  author, 
sen.  Tim  Scott  (R-SC),  "warned  against  a  partisan,  political  debate  that 
chisels  away  confidence  in  the  nation's  institutions."  Reuters 
[6/23,  Morgan)  similarly  says  "Democrats  and  Republicans.. .found 
themselves  in  a  partisan  deadlock  on  Tuesday." 

AP-NORC  Poll:  Nearly  All  Americans  Back  Some  Kind  Of 
Criminal  Justice  Reform.  The  AP  I  B(6/23,  Long,  Fingerhut)  reports  that  Americans  "overwhelmingly  want  clear  standards 
on  when  police  officers  may  use  force  and  consequences  for  officers  who  do  so  excessively,  according  to  a  new  poll  that  finds 
nearly  all  Americans  favor  at  least  some  level  of  change  to  the  nation's  criminal  justice  system."  The  new  AP-NORC  poll  "also 
finds  there  is  strong  support  for  penalizing  officers  who  engage  in  racially  biased  policing." 

Confronting  Nazi  Legacy  Part  Of  German  Police  Training 

The  New  York  Times  (6/23,  Bennhold,  Eddy)  reports  that  "visiting  a  former  concentration  camp  is  mandatory  for  every 


future  police  officer  in  Berlin."  To  the  Times,  it  is  "one  of  the  ways  in  which  policing  was  fundamentally  overhauled  in  Germany 
afterWorld  Warll." 

Rhode  Island  Governor  Signs  Ban  On  3D-Printed  Weapons,  "Ghost  Guns" 

The  AP  (6/23,  Pratt)  reports  that  Rhode  Island  Gov.  Gina  Raimondo  "on  Tuesday  signed  into  law  bills  that  ban  3D-printed 
guns  and  so-called  'ghost  guns'  in  the  state."  The  bills  "are  'a  matter  of  public  health,'  she  said."  The  bills  "were  approved  by 
the  legislature  last  week,"  and  "make  it  illegal  to  manufacture,  import,  sell,  ship,  deliver,  possess,  transfer  or  receive  any  such 
firearms.  Anyone  who  violates  the  ban  and  is  convicted  could  serve  up  to  10  years  in  prison  and  faces  fines  of  up  $10,000.  The 
laws  take  effect  in  30  days." 

Seattle,  Washington  To  End  Anti-Loitering  Law 

Fox  News  (6/23,  Carter)  reports,  "Seattle  is  moving  to  end  a  longstanding  city  law  that  allowed  police  to  arrest  someone 
for  loitering,  if  they  are  also  suspected  of  being  a  possible  drug  offender  or  sex  worker."  According  to  Fox  News,  "The  twin  bills, 
passed  unanimously  by  the  Seattle  City  Council  Monday,  effectively  block  authorities  from  arresting  someone  for  loitering  in 
relation  to  a  drug  or  a  prostitution  inquiry.  Both  laws,  according  to  the  Chicago-Kent  Law  Review,  have  historically  targeted 
people  of  color." 

Georgia  Lawmakers  Pass  Bills  On  Hate  Crimes,  Enhanced  Police  Protections 

The  AP  (6/23,  Nadler,  Amy)  reports,  "Georgia's  legislature  on  Tuesday  passed  hate  crimes  legislation  deemed  essential  by 
business  and  many  political  leaders,  sending  the  measure  to  Gov.  Brian  Kemp's  desk.  The  price  Republicans  exacted  for  moving 
that  legislation  forward  was  simultaneous  passage  of  a  separate  bill  that  would  mandate  penalties  for  crimes  targeting  police 
and  other  first  responders."  According  to  the  AP,  "The  action  comes  after  Senate  Republicans  had  added  police  as  a  protected 
class  to  the  hate  crimes  legislation  last  week  in  committee,  but  then  later  moved  those  protections  to  a  separate  bill  in  a  deal 
between  the  parties.  Democrats  on  Tuesday  voted  overwhelmingly  against  House  Bill  838,  which  includes  the  increased 
protections  for  first  responders.  The  hate  crimes  legislation,  House  Bill  426,  had  bipartisan  support." 


The  impact  of  an  officer's  line-of-duty  injury  may  continue  beyond  the  initial  event  and  hospitalization.  Agencies 
can  prepare  to  provide  resources  such  as  behavioral  health  and  wellness  or  peer  support  services  to  officers  and 
their  families.  The  Line-of-Duty  Serious  Injury  Considerations  document  and  Concepts  &  Issues  paper  from  the 
IACP  Law  Enforcement  Policy  Center  provides  guidelines  for  agencies  to  consider. 
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CRIME  &  DRUGS 


Law  Enforcement  Concerned  About  Rash  Of  Gun-Store  Robberies 

Politico  (6/23,  Swan)  reports,  "A  rash  of  gun-store  burglaries  has  alarmed  law  enforcement  officials,  and  comes  amid 
widespread  protests  that  have  been  accompanied  by  incidents  of  looting  and  vandalism  across  the  country."  According  to 
Politico,  "In  the  last  days  of  May  and  first  week  of  June,  there  were  more  than  90  attempted  or  successful  burglaries  of  gun 
stores,  according  to  the  Bureau  of  Alcohol,  Tobacco,  and  Firearms  (ATF).  More  than  1,000  guns  were  stolen  in  that  window  of 
time,  the  bureau's  assistant  director  of  field  operations  Tom  Chittum  told  POLITICO.  'It's  a  lot  of  guns,'  Chittum  said  in  an 
interview.  'It's  the  biggest  spike  I  have  ever  seen  of  gun  store  burglaries.'"  Chittum  "said  investigations  into  the  surge  of  gun 
store  burglaries  are  underway,  and  that  some  of  the  burglaries  appeared  to  be  part  of  broader  looting.  Other  cases,  he  added, 
may  have  been  the  work  of  opportunists." 


Gun  Violence  Spikes  In  New  York  City 

The  New  York  Times  (6/23,  Southall,  Macfarquhar)  reports,  "It  has  been  nearly  a  quarter  century  since  New  York  City 
experienced  as  much  gun  violence  in  the  month  of  June  as  it  has  seen  this  year."  The  city  "logged  125  shootings  in  the  first 
three  weeks  of  the  month,  more  than  double  the  number  recorded  over  in  same  period  last  year,  police  data  show.  Gunmen 
opened  fire  during  house  parties,  barbecues,  dice  games,  and  carried  out  coldly  calculated  street  executions."  New  York  "is  not 
alone.  Shootings  are  on  the  rise  in  other  big  cities  across  the  country,  including  Chicago  and  Minneapolis,  a  trend  that  some 
conservatives  have  seized  on  to  argue  against  the  recent  demands  of  protesters  to  cut  police  budgets  and  rein  in  officers."  On 
Monday,  Mayor  Bill  de  Blasio  "announced  that  the  city  was  sending  more  officers  into  the  streets  and  declared  he  would  not 
retreat  from  efforts  to  overhaul  the  Police  Department." 

Federal,  Local  Authorities  Arrest  14  Suspects  In  South  Carolina  Car-Jacking,  Drug  Ring 

The  Columbia  TSC)  State  I  (6/23,  Monk)  reports,  "More  than  200  federal  and  local  law  enforcement  officers  on  Tuesday 

rounded  up  14  members  of  an  alleged  Columbia-area  violent  gang  whose  members  specialized  in  carjackings,  armed  robberies 
and  drug  dealing."  According  to  US  Attorney  Peter  McCoy,  who  announced  the  arrests  Tuesday,  the  arrests  "were  the  result  of 
a  nearly  two-year  investigation  by  the  FBI,  the  DEA  and  local  law  enforcement  into  a  spike  in  gang-related  violence  in  Richland, 
Lexington  and  Kershaw  counties  that  began  in  July  2018."  FBI  South  Carolina  SAC  Jody  Norris  said,  "Even  in  the  midst  of  a 
pandemic,  the  FBI  and  its  task  forces  will  continue  to  find  and  arrest  drug  traffickers  who  work  against  the  people  of  South 
Carolina."  Also  reporting  are  WACH-TV  IHIcolumbia,  SC  (6/23,  Lanahan)  and  WIS-TV  Bicolumbia,  SC  (6/23,  Greene). 

GLOBAL  SECURITY 


Suicide  Bomber  Targets  Turkish  Military  Base  In  Somalia 

The  New  York  Times  (6/23,  Mohamed,  Dahir)  reports,  "Two  people  were  killed  after  a  suicide  bomber  detonated  his 
explosives  outside  Turkey's  largest  overseas  military  base  in  Mogadishu  on  Tuesday."  The  attack,  which  the  Times  says  "bears 
the  hallmarks  of  the  Shabab  terrorist  group,  was  carried  out  just  before  9  a.m.  as  recruits  lined  up  for  enlistment  at  Camp 
Turksom,  where  hundreds  of  Somali  soldiers  are  trained  and  the  new  enrollment  of  dozens  was  underway." 

The  AP  (6/23,  Guled)  says  Tuesday's  attack  marks  "the  first  time  Turkey's  largest  overseas  military  base  has  been 
attacked  by  the  al-Qaida-linked  al-Shabab  extremist  group,"  which  "quickly  claimed  responsibility,  according  to  its  Radio  al- 
Furqan  affiliate." 

Secret  Recordings  Detail  Neo-Nazi  Group's  Grooming,  Recruiting  Process 

Fox  News  (6/23,  Chakraborty)  reports  on  newly  revealed  secret  recordings,  first  reported  by  the  BBC,  which  show  "senior 
members  of  The  Base,  a  hate  group  started  in  the  United  States,  interviewing  young  applicants,  discussing  their  prospects  and 
ways  to  radicalize  them."  The  founder  of  the  group,  American  Rinaldo  Nazzaro,  "who  now  directs  members  of  his  group  from 
St.  Petersburg,  Russia,  is  heard  asking  prospective  members  about  their  ethnicity,  radicalization  journey  and  their  experience 
with  weapons."  Fox  reports  Nazzaro  "purportedly  worked  as  an  analyst  for  the  FBI  and  as  a  contractor  for  the  Pentagon  before 
he  left  New  York  for  Russia  less  than  two  years  ago." 

ALSO  IN  THE  NEWS 

FCC  To  Vote  Next  Month  On  Making  "988"  New  Suicide  Hotline  Number 

The  AP  (6/23,  Arbel)  reports  the  FCC  "will  vote  in  July  on  whether  to  make  '988'  the  number  to  reach  a  suicide  prevention 
hotline."  The  Commission  explained  that  "phone  service  providers  will  have  until  July  2022  to  implement  the  new  number,  if 
the  measure  is  approved  in  July,  as  expected." 
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POLICING  &  POLICY 


Top  Senate  Democrats  Dismiss  Republican  Policing 
Reform  Bill 

The  AP  (6/23,  Mascaro)  reports  Congress  is  "hitting  an  impasse  on 
aolicing  legislation,  as  key  Senate  Democrats  on  Tuesday  opposed  a 
Republican  proposal  as  inadequate,  leaving  the  parties  to  decide 
whether  to  take  on  the  hard  job  of  negotiating  a  compromise  or  walk 
away."  Ahead  of  a  test  vote  Wednesday,  Senate  Majority  Leader 
McConnell  "acknowledged  it  may  fall  short,"  and  the  GOP  bill's  author, 
sen.  Tim  Scott  (R-SC),  "warned  against  a  partisan,  political  debate  that 
chisels  away  confidence  in  the  nation's  institutions."  Reuters 
[6/23,  Morgan)  similarly  says  "Democrats  and  Republicans.. .found 
themselves  in  a  partisan  deadlock  on  Tuesday." 

AP-NORC  Poll:  Nearly  All  Americans  Back  Some  Kind  Of 
Criminal  Justice  Reform.  The  AP  I  B(6/23,  Long,  Fingerhut)  reports  that  Americans  "overwhelmingly  want  clear  standards 
on  when  police  officers  may  use  force  and  consequences  for  officers  who  do  so  excessively,  according  to  a  new  poll  that  finds 
nearly  all  Americans  favor  at  least  some  level  of  change  to  the  nation's  criminal  justice  system."  The  new  AP-NORC  poll  "also 
finds  there  is  strong  support  for  penalizing  officers  who  engage  in  racially  biased  policing." 

Confronting  Nazi  Legacy  Part  Of  German  Police  Training 

The  New  York  Times  (6/23,  Bennhold,  Eddy)  reports  that  "visiting  a  former  concentration  camp  is  mandatory  for  every 


future  police  officer  in  Berlin."  To  the  Times,  it  is  "one  of  the  ways  in  which  policing  was  fundamentally  overhauled  in  Germany 
afterWorld  Warll." 

Rhode  Island  Governor  Signs  Ban  On  3D-Printed  Weapons,  "Ghost  Guns" 

The  AP  (6/23,  Pratt)  reports  that  Rhode  Island  Gov.  Gina  Raimondo  "on  Tuesday  signed  into  law  bills  that  ban  3D-printed 
guns  and  so-called  'ghost  guns'  in  the  state."  The  bills  "are  'a  matter  of  public  health,'  she  said."  The  bills  "were  approved  by 
the  legislature  last  week,"  and  "make  it  illegal  to  manufacture,  import,  sell,  ship,  deliver,  possess,  transfer  or  receive  any  such 
firearms.  Anyone  who  violates  the  ban  and  is  convicted  could  serve  up  to  10  years  in  prison  and  faces  fines  of  up  $10,000.  The 
laws  take  effect  in  30  days." 

Seattle,  Washington  To  End  Anti-Loitering  Law 

Fox  News  (6/23,  Carter)  reports,  "Seattle  is  moving  to  end  a  longstanding  city  law  that  allowed  police  to  arrest  someone 
for  loitering,  if  they  are  also  suspected  of  being  a  possible  drug  offender  or  sex  worker."  According  to  Fox  News,  "The  twin  bills, 
passed  unanimously  by  the  Seattle  City  Council  Monday,  effectively  block  authorities  from  arresting  someone  for  loitering  in 
relation  to  a  drug  or  a  prostitution  inquiry.  Both  laws,  according  to  the  Chicago-Kent  Law  Review,  have  historically  targeted 
people  of  color." 

Georgia  Lawmakers  Pass  Bills  On  Hate  Crimes,  Enhanced  Police  Protections 

The  AP  (6/23,  Nadler,  Amy)  reports,  "Georgia's  legislature  on  Tuesday  passed  hate  crimes  legislation  deemed  essential  by 
business  and  many  political  leaders,  sending  the  measure  to  Gov.  Brian  Kemp's  desk.  The  price  Republicans  exacted  for  moving 
that  legislation  forward  was  simultaneous  passage  of  a  separate  bill  that  would  mandate  penalties  for  crimes  targeting  police 
and  other  first  responders."  According  to  the  AP,  "The  action  comes  after  Senate  Republicans  had  added  police  as  a  protected 
class  to  the  hate  crimes  legislation  last  week  in  committee,  but  then  later  moved  those  protections  to  a  separate  bill  in  a  deal 
between  the  parties.  Democrats  on  Tuesday  voted  overwhelmingly  against  House  Bill  838,  which  includes  the  increased 
protections  for  first  responders.  The  hate  crimes  legislation,  House  Bill  426,  had  bipartisan  support." 


The  impact  of  an  officer's  line-of-duty  injury  may  continue  beyond  the  initial  event  and  hospitalization.  Agencies 
can  prepare  to  provide  resources  such  as  behavioral  health  and  wellness  or  peer  support  services  to  officers  and 
their  families.  The  Line-of-Duty  Serious  Injury  Considerations  document  and  Concepts  &  Issues  paper  from  the 
IACP  Law  Enforcement  Policy  Center  provides  guidelines  for  agencies  to  consider. 
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CRIME  &  DRUGS 


Law  Enforcement  Concerned  About  Rash  Of  Gun-Store  Robberies 

Politico  (6/23,  Swan)  reports,  "A  rash  of  gun-store  burglaries  has  alarmed  law  enforcement  officials,  and  comes  amid 
widespread  protests  that  have  been  accompanied  by  incidents  of  looting  and  vandalism  across  the  country."  According  to 
Politico,  "In  the  last  days  of  May  and  first  week  of  June,  there  were  more  than  90  attempted  or  successful  burglaries  of  gun 
stores,  according  to  the  Bureau  of  Alcohol,  Tobacco,  and  Firearms  (ATF).  More  than  1,000  guns  were  stolen  in  that  window  of 
time,  the  bureau's  assistant  director  of  field  operations  Tom  Chittum  told  POLITICO.  'It's  a  lot  of  guns,'  Chittum  said  in  an 
interview.  'It's  the  biggest  spike  I  have  ever  seen  of  gun  store  burglaries.'"  Chittum  "said  investigations  into  the  surge  of  gun 
store  burglaries  are  underway,  and  that  some  of  the  burglaries  appeared  to  be  part  of  broader  looting.  Other  cases,  he  added, 
may  have  been  the  work  of  opportunists." 


Gun  Violence  Spikes  In  New  York  City 

The  New  York  Times  (6/23,  Southall,  Macfarquhar)  reports,  "It  has  been  nearly  a  quarter  century  since  New  York  City 
experienced  as  much  gun  violence  in  the  month  of  June  as  it  has  seen  this  year."  The  city  "logged  125  shootings  in  the  first 
three  weeks  of  the  month,  more  than  double  the  number  recorded  over  in  same  period  last  year,  police  data  show.  Gunmen 
opened  fire  during  house  parties,  barbecues,  dice  games,  and  carried  out  coldly  calculated  street  executions."  New  York  "is  not 
alone.  Shootings  are  on  the  rise  in  other  big  cities  across  the  country,  including  Chicago  and  Minneapolis,  a  trend  that  some 
conservatives  have  seized  on  to  argue  against  the  recent  demands  of  protesters  to  cut  police  budgets  and  rein  in  officers."  On 
Monday,  Mayor  Bill  de  Blasio  "announced  that  the  city  was  sending  more  officers  into  the  streets  and  declared  he  would  not 
retreat  from  efforts  to  overhaul  the  Police  Department." 

Federal,  Local  Authorities  Arrest  14  Suspects  In  South  Carolina  Car-Jacking,  Drug  Ring 

The  Columbia  TSC)  State  I  (6/23,  Monk)  reports,  "More  than  200  federal  and  local  law  enforcement  officers  on  Tuesday 

rounded  up  14  members  of  an  alleged  Columbia-area  violent  gang  whose  members  specialized  in  carjackings,  armed  robberies 
and  drug  dealing."  According  to  US  Attorney  Peter  McCoy,  who  announced  the  arrests  Tuesday,  the  arrests  "were  the  result  of 
a  nearly  two-year  investigation  by  the  FBI,  the  DEA  and  local  law  enforcement  into  a  spike  in  gang-related  violence  in  Richland, 
Lexington  and  Kershaw  counties  that  began  in  July  2018."  FBI  South  Carolina  SAC  Jody  Norris  said,  "Even  in  the  midst  of  a 
pandemic,  the  FBI  and  its  task  forces  will  continue  to  find  and  arrest  drug  traffickers  who  work  against  the  people  of  South 
Carolina."  Also  reporting  are  WACH-TV  IHIcolumbia,  SC  (6/23,  Lanahan)  and  WIS-TV  Bicolumbia,  SC  (6/23,  Greene). 

GLOBAL  SECURITY 


Suicide  Bomber  Targets  Turkish  Military  Base  In  Somalia 

The  New  York  Times  (6/23,  Mohamed,  Dahir)  reports,  "Two  people  were  killed  after  a  suicide  bomber  detonated  his 
explosives  outside  Turkey's  largest  overseas  military  base  in  Mogadishu  on  Tuesday."  The  attack,  which  the  Times  says  "bears 
the  hallmarks  of  the  Shabab  terrorist  group,  was  carried  out  just  before  9  a.m.  as  recruits  lined  up  for  enlistment  at  Camp 
Turksom,  where  hundreds  of  Somali  soldiers  are  trained  and  the  new  enrollment  of  dozens  was  underway." 

The  AP  (6/23,  Guled)  says  Tuesday's  attack  marks  "the  first  time  Turkey's  largest  overseas  military  base  has  been 
attacked  by  the  al-Qaida-linked  al-Shabab  extremist  group,"  which  "quickly  claimed  responsibility,  according  to  its  Radio  al- 
Furqan  affiliate." 

Secret  Recordings  Detail  Neo-Nazi  Group's  Grooming,  Recruiting  Process 

Fox  News  (6/23,  Chakraborty)  reports  on  newly  revealed  secret  recordings,  first  reported  by  the  BBC,  which  show  "senior 
members  of  The  Base,  a  hate  group  started  in  the  United  States,  interviewing  young  applicants,  discussing  their  prospects  and 
ways  to  radicalize  them."  The  founder  of  the  group,  American  Rinaldo  Nazzaro,  "who  now  directs  members  of  his  group  from 
St.  Petersburg,  Russia,  is  heard  asking  prospective  members  about  their  ethnicity,  radicalization  journey  and  their  experience 
with  weapons."  Fox  reports  Nazzaro  "purportedly  worked  as  an  analyst  for  the  FBI  and  as  a  contractor  for  the  Pentagon  before 
he  left  New  York  for  Russia  less  than  two  years  ago." 

ALSO  IN  THE  NEWS 

FCC  To  Vote  Next  Month  On  Making  "988"  New  Suicide  Hotline  Number 

The  AP  (6/23,  Arbel)  reports  the  FCC  "will  vote  in  July  on  whether  to  make  '988'  the  number  to  reach  a  suicide  prevention 
hotline."  The  Commission  explained  that  "phone  service  providers  will  have  until  July  2022  to  implement  the  new  number,  if 
the  measure  is  approved  in  July,  as  expected." 

TUESDAY'S  LEAD  STORIES 


•  US  Supreme  Court  Will  Not  Revisit  Challenge  To  Qualified  Immunity  For  Police 

•  Swedish  Rape  Conviction  Rates  Rise  75%  After  Change  In  Law 

•  "Blueleaks"  Hackers  Release  "Hundreds  Of  Thousands"  Of  Private  Records  On  Officers 
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POLICING  &  POLICY 


Top  Senate  Democrats  Dismiss  Republican  Policing 
Reform  Bill 

The  AP  (6/23,  Mascaro)  reports  Congress  is  "hitting  an  impasse  on 
aolicing  legislation,  as  key  Senate  Democrats  on  Tuesday  opposed  a 
Republican  proposal  as  inadequate,  leaving  the  parties  to  decide 
whether  to  take  on  the  hard  job  of  negotiating  a  compromise  or  walk 
away."  Ahead  of  a  test  vote  Wednesday,  Senate  Majority  Leader 
McConnell  "acknowledged  it  may  fall  short,"  and  the  GOP  bill's  author, 
sen.  Tim  Scott  (R-SC),  "warned  against  a  partisan,  political  debate  that 
chisels  away  confidence  in  the  nation's  institutions."  Reuters 
[6/23,  Morgan)  similarly  says  "Democrats  and  Republicans.. .found 
themselves  in  a  partisan  deadlock  on  Tuesday." 

AP-NORC  Poll:  Nearly  All  Americans  Back  Some  Kind  Of  Criminal  Justice  Reform.  The  AP  (6/23,  Long, 
Fingerhut)  reports  that  Americans  "overwhelmingly  want  clear  standards  on  when  police  officers  may  use  force  and 
consequences  for  officers  who  do  so  excessively,  according  to  a  new  poll  that  finds  nearly  all  Americans  favor  at  least  some 
level  of  change  to  the  nation's  criminal  justice  system."  The  new  AP-NORC  poll  "also  finds  there  is  strong  support  for  penalizing 
officers  who  engage  in  racially  biased  policing." 

Confronting  Nazi  Legacy  Part  Of  German  Police  Training 

The  New  York  Times  (6/23,  Bennhold,  Eddy)  reports  that  "visiting  a  former  concentration  camp  is  mandatory  for  every 
future  police  officer  in  Berlin."  To  the  Times,  it  is  "one  of  the  ways  in  which  policing  was  fundamentally  overhauled  in  Germany 
afterWorld  Warll." 

Rhode  Island  Governor  Signs  Ban  On  3D-Printed  Weapons,  "Ghost  Guns" 

The  AP  (6/23,  Pratt)  reports  that  Rhode  Island  Gov.  Gina  Raimondo  "on  Tuesday  signed  into  law  bills  that  ban  3D-printed 
guns  and  so-called  'ghost  guns'  in  the  state."  The  bills  "are  'a  matter  of  public  health,'  she  said."  The  bills  "were  approved  by 
the  legislature  last  week,"  and  "make  it  illegal  to  manufacture,  import,  sell,  ship,  deliver,  possess,  transfer  or  receive  any  such 
firearms.  Anyone  who  violates  the  ban  and  is  convicted  could  serve  up  to  10  years  in  prison  and  faces  fines  of  up  $10,000.  The 
laws  take  effect  in  30  days." 

Seattle,  Washington  To  End  Anti-Loitering  Law 

Fox  News  (6/23,  Carter)  reports,  "Seattle  is  moving  to  end  a  longstanding  city  law  that  allowed  police  to  arrest  someone 
for  loitering,  if  they  are  also  suspected  of  being  a  possible  drug  offender  or  sex  worker."  According  to  Fox  News,  "The  twin  bills, 
passed  unanimously  by  the  Seattle  City  Council  Monday,  effectively  block  authorities  from  arresting  someone  for  loitering  in 
relation  to  a  drug  or  a  prostitution  inquiry.  Both  laws,  according  to  the  Chicago-Kent  Law  Review,  have  historically  targeted 
people  of  color." 

Georgia  Lawmakers  Pass  Bills  On  Hate  Crimes,  Enhanced  Police  Protections 

The  AP  (6/23,  Nadler,  Amy)  reports,  "Georgia's  legislature  on  Tuesday  passed  hate  crimes  legislation  deemed  essential  by 
business  and  many  political  leaders,  sending  the  measure  to  Gov.  Brian  Kemp's  desk.  The  price  Republicans  exacted  for  moving 
that  legislation  forward  was  simultaneous  passage  of  a  separate  bill  that  would  mandate  penalties  for  crimes  targeting  police 
and  other  first  responders."  According  to  the  AP,  "The  action  comes  after  Senate  Republicans  had  added  police  as  a  protected 
class  to  the  hate  crimes  legislation  last  week  in  committee,  but  then  later  moved  those  protections  to  a  separate  bill  in  a  deal 
between  the  parties.  Democrats  on  Tuesday  voted  overwhelmingly  against  House  Bill  838,  which  includes  the  increased 
protections  for  first  responders.  The  hate  crimes  legislation,  House  Bill  426,  had  bipartisan  support." 


The  impact  of  an  officer's  line-of-duty  injury  may  continue  beyond  the  initial  event  and  hospitalization.  Agencies 
can  prepare  to  provide  resources  such  as  behavioral  health  and  wellness  or  peer  support  services  to  officers  and 
their  families.  The  Line-of-Duty  Serious  Injury  Considerations  document  and  Concepts  &  Issues  paper  from  the 
IACP  Law  Enforcement  Policy  Center  provides  guidelines  for  agencies  to  consider. 
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CRIME  &  DRUGS 


Law  Enforcement  Concerned  About  Rash  Of  Gun-Store  Robberies 

Politico  (6/23,  Swan)  reports,  "A  rash  of  gun-store  burglaries  has  alarmed  law  enforcement  officials,  and  comes  amid 
widespread  protests  that  have  been  accompanied  by  incidents  of  looting  and  vandalism  across  the  country."  According  to 
Politico,  "In  the  last  days  of  May  and  first  week  of  June,  there  were  more  than  90  attempted  or  successful  burglaries  of  gun 
stores,  according  to  the  Bureau  of  Alcohol,  Tobacco,  and  Firearms  (ATF).  More  than  1,000  guns  were  stolen  in  that  window  of 
time,  the  bureau's  assistant  director  of  field  operations  Tom  Chittum  told  POLITICO.  'It's  a  lot  of  guns,'  Chittum  said  in  an 
interview.  'It's  the  biggest  spike  I  have  ever  seen  of  gun  store  burglaries.'"  Chittum  "said  investigations  into  the  surge  of  gun 
store  burglaries  are  underway,  and  that  some  of  the  burglaries  appeared  to  be  part  of  broader  looting.  Other  cases,  he  added, 
may  have  been  the  work  of  opportunists." 

Gun  Violence  Spikes  In  New  York  City 

The  New  York  Times  (6/23,  Southall,  Macfarquhar)  reports,  "It  has  been  nearly  a  quarter  century  since  New  York  City 
experienced  as  much  gun  violence  in  the  month  of  June  as  it  has  seen  this  year."  The  city  "logged  125  shootings  in  the  first 
three  weeks  of  the  month,  more  than  double  the  number  recorded  over  in  same  period  last  year,  police  data  show.  Gunmen 
opened  fire  during  house  parties,  barbecues,  dice  games,  and  carried  out  coldly  calculated  street  executions."  New  York  "is  not 
alone.  Shootings  are  on  the  rise  in  other  big  cities  across  the  country,  including  Chicago  and  Minneapolis,  a  trend  that  some 
conservatives  have  seized  on  to  argue  against  the  recent  demands  of  protesters  to  cut  police  budgets  and  rein  in  officers."  On 
Monday,  Mayor  Bill  de  Blasio  "announced  that  the  city  was  sending  more  officers  into  the  streets  and  declared  he  would  not 
retreat  from  efforts  to  overhaul  the  Police  Department." 

Federal,  Local  Authorities  Arrest  14  Suspects  In  South  Carolina  Car-Jacking,  Drug  Ring 

The  Columbia  (SC)  State  (6/23,  Monk)  reports,  "More  than  200  federal  and  local  law  enforcement  officers  on  Tuesday 
rounded  up  14  members  of  an  alleged  Columbia-area  violent  gang  whose  members  specialized  in  carjackings,  armed  robberies 
and  drug  dealing."  According  to  US  Attorney  Peter  McCoy,  who  announced  the  arrests  Tuesday,  the  arrests  "were  the  result  of 
a  nearly  two-year  investigation  by  the  FBI,  the  DEA  and  local  law  enforcement  into  a  spike  in  gang-related  violence  in  Richland, 
Lexington  and  Kershaw  counties  that  began  in  July  2018."  FBI  South  Carolina  SAC  Jody  Norris  said,  "Even  in  the  midst  of  a 
pandemic,  the  FBI  and  its  task  forces  will  continue  to  find  and  arrest  drug  traffickers  who  work  against  the  people  of  South 
Carolina."  Also  reporting  are  WACH-TV  HHcolumbia,  SC  (6/23,  Lanahan)  and  WIS-TV  HBcolumbia,  SC  (6/23,  Greene). 

GLOBAL  SECURITY 


Suicide  Bomber  Targets  Turkish  Military  Base  In  Somalia 

The  New  York  Times  (6/23,  Mohamed,  Dahir)  reports,  "Two  people  were  killed  after  a  suicide  bomber  detonated  his 
explosives  outside  Turkey's  largest  overseas  military  base  in  Mogadishu  on  Tuesday."  The  attack,  which  the  Times  says  "bears 
the  hallmarks  of  the  Shabab  terrorist  group,  was  carried  out  just  before  9  a.m.  as  recruits  lined  up  for  enlistment  at  Camp 
Turksom,  where  hundreds  of  Somali  soldiers  are  trained  and  the  new  enrollment  of  dozens  was  underway." 

The  AP  (6/23,  Guled)  says  Tuesday's  attack  marks  "the  first  time  Turkey's  largest  overseas  military  base  has  been 


attacked  by  the  al-Qaida-linked  al-Shabab  extremist  group/'  which  "quickly  claimed  responsibility,  according  to  its  Radio  al- 
Furqan  affiliate." 

Secret  Recordings  Detail  Neo-Nazi  Group's  Grooming,  Recruiting  Process 

Fox  News  (6/23,  Chakraborty)  reports  on  newly  revealed  secret  recordings,  first  reported  by  the  BBC,  which  show  "senior 
members  of  The  Base,  a  hate  group  started  in  the  United  States,  interviewing  young  applicants,  discussing  their  prospects  and 
ways  to  radicalize  them."  The  founder  of  the  group,  American  Rinaldo  Nazzaro,  "who  now  directs  members  of  his  group  from 
St.  Petersburg,  Russia,  is  heard  asking  prospective  members  about  their  ethnicity,  radicalization  journey  and  their  experience 
with  weapons."  Fox  reports  Nazzaro  "purportedly  worked  as  an  analyst  for  the  FBI  and  as  a  contractor  for  the  Pentagon  before 
he  left  New  York  for  Russia  less  than  two  years  ago." 

ALSO  IN  THE  NEWS 


FCC  To  Vote  Next  Month  On  Making  "988"  New  Suicide  Hotline  Number 

The  AP  (6/23,  Arbel)  reports  the  FCC  "will  vote  in  July  on  whether  to  make  '988'  the  number  to  reach  a  suicide  prevention 
hotline."  The  Commission  explained  that  "phone  service  providers  will  have  until  July  2022  to  implement  the  new  number,  if 
the  measure  is  approved  in  July,  as  expected." 
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POLICING  &  POLICY 


Top  Senate  Democrats  Dismiss  Republican  Policing 
Reform  Bill 

The  AP  (6/23,  Mascaro)  reports  Congress  is  "hitting  an  impasse  on 
aolicing  legislation,  as  key  Senate  Democrats  on  Tuesday  opposed  a 
Republican  proposal  as  inadequate,  leaving  the  parties  to  decide 
whether  to  take  on  the  hard  job  of  negotiating  a  compromise  or  walk 
away."  Ahead  of  a  test  vote  Wednesday,  Senate  Majority  Leader 
McConnell  "acknowledged  it  may  fall  short,"  and  the  GOP  bill's  author, 
sen.  Tim  Scott  (R-SC),  "warned  against  a  partisan,  political  debate  that 
chisels  away  confidence  in  the  nation's  institutions."  Reuters 
[6/23,  Morgan)  similarly  says  "Democrats  and  Republicans.. .found 
themselves  in  a  partisan  deadlock  on  Tuesday." 

AP-NORC  Poll:  Nearly  All  Americans  Back  Some  Kind  Of  Criminal  Justice  Reform.  The  AP  (6/23,  Long, 
Fingerhut)  reports  that  Americans  "overwhelmingly  want  clear  standards  on  when  police  officers  may  use  force  and 
consequences  for  officers  who  do  so  excessively,  according  to  a  new  poll  that  finds  nearly  all  Americans  favor  at  least  some 
level  of  change  to  the  nation's  criminal  justice  system."  The  new  AP-NORC  poll  "also  finds  there  is  strong  support  for  penalizing 
officers  who  engage  in  racially  biased  policing." 

Confronting  Nazi  Legacy  Part  Of  German  Police  Training 

The  New  York  Times  (6/23,  Bennhold,  Eddy)  reports  that  "visiting  a  former  concentration  camp  is  mandatory  for  every 
future  police  officer  in  Berlin."  To  the  Times,  it  is  "one  of  the  ways  in  which  policing  was  fundamentally  overhauled  in  Germany 
afterWorld  Warll." 

Rhode  Island  Governor  Signs  Ban  On  3D-Printed  Weapons,  "Ghost  Guns" 

The  AP  (6/23,  Pratt)  reports  that  Rhode  Island  Gov.  Gina  Raimondo  "on  Tuesday  signed  into  law  bills  that  ban  3D-printed 
guns  and  so-called  'ghost  guns'  in  the  state."  The  bills  "are  'a  matter  of  public  health,'  she  said."  The  bills  "were  approved  by 
the  legislature  last  week,"  and  "make  it  illegal  to  manufacture,  import,  sell,  ship,  deliver,  possess,  transfer  or  receive  any  such 
firearms.  Anyone  who  violates  the  ban  and  is  convicted  could  serve  up  to  10  years  in  prison  and  faces  fines  of  up  $10,000.  The 
laws  take  effect  in  30  days." 

Seattle,  Washington  To  End  Anti-Loitering  Law 

Fox  News  (6/23,  Carter)  reports,  "Seattle  is  moving  to  end  a  longstanding  city  law  that  allowed  police  to  arrest  someone 
for  loitering,  if  they  are  also  suspected  of  being  a  possible  drug  offender  or  sex  worker."  According  to  Fox  News,  "The  twin  bills, 
passed  unanimously  by  the  Seattle  City  Council  Monday,  effectively  block  authorities  from  arresting  someone  for  loitering  in 
relation  to  a  drug  or  a  prostitution  inquiry.  Both  laws,  according  to  the  Chicago-Kent  Law  Review,  have  historically  targeted 
people  of  color." 

Georgia  Lawmakers  Pass  Bills  On  Hate  Crimes,  Enhanced  Police  Protections 

The  AP  (6/23,  Nadler,  Amy)  reports,  "Georgia's  legislature  on  Tuesday  passed  hate  crimes  legislation  deemed  essential  by 
business  and  many  political  leaders,  sending  the  measure  to  Gov.  Brian  Kemp's  desk.  The  price  Republicans  exacted  for  moving 
that  legislation  forward  was  simultaneous  passage  of  a  separate  bill  that  would  mandate  penalties  for  crimes  targeting  police 
and  other  first  responders."  According  to  the  AP,  "The  action  comes  after  Senate  Republicans  had  added  police  as  a  protected 
class  to  the  hate  crimes  legislation  last  week  in  committee,  but  then  later  moved  those  protections  to  a  separate  bill  in  a  deal 
between  the  parties.  Democrats  on  Tuesday  voted  overwhelmingly  against  House  Bill  838,  which  includes  the  increased 
protections  for  first  responders.  The  hate  crimes  legislation,  House  Bill  426,  had  bipartisan  support." 


The  impact  of  an  officer's  line-of-duty  injury  may  continue  beyond  the  initial  event  and  hospitalization.  Agencies 
can  prepare  to  provide  resources  such  as  behavioral  health  and  wellness  or  peer  support  services  to  officers  and 
their  families.  The  Line-of-Duty  Serious  Injury  Considerations  document  and  Concepts  &  Issues  paper  from  the 
IACP  Law  Enforcement  Policy  Center  provides  guidelines  for  agencies  to  consider. 
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CRIME  &  DRUGS 


Law  Enforcement  Concerned  About  Rash  Of  Gun-Store  Robberies 

Politico  (6/23,  Swan)  reports,  "A  rash  of  gun-store  burglaries  has  alarmed  law  enforcement  officials,  and  comes  amid 
widespread  protests  that  have  been  accompanied  by  incidents  of  looting  and  vandalism  across  the  country."  According  to 
Politico,  "In  the  last  days  of  May  and  first  week  of  June,  there  were  more  than  90  attempted  or  successful  burglaries  of  gun 
stores,  according  to  the  Bureau  of  Alcohol,  Tobacco,  and  Firearms  (ATF).  More  than  1,000  guns  were  stolen  in  that  window  of 
time,  the  bureau's  assistant  director  of  field  operations  Tom  Chittum  told  POLITICO.  'It's  a  lot  of  guns,'  Chittum  said  in  an 
interview.  'It's  the  biggest  spike  I  have  ever  seen  of  gun  store  burglaries.'"  Chittum  "said  investigations  into  the  surge  of  gun 
store  burglaries  are  underway,  and  that  some  of  the  burglaries  appeared  to  be  part  of  broader  looting.  Other  cases,  he  added, 
may  have  been  the  work  of  opportunists." 

Gun  Violence  Spikes  In  New  York  City 

The  New  York  Times  (6/23,  Southall,  Macfarquhar)  reports,  "It  has  been  nearly  a  quarter  century  since  New  York  City 
experienced  as  much  gun  violence  in  the  month  of  June  as  it  has  seen  this  year."  The  city  "logged  125  shootings  in  the  first 
three  weeks  of  the  month,  more  than  double  the  number  recorded  over  in  same  period  last  year,  police  data  show.  Gunmen 
opened  fire  during  house  parties,  barbecues,  dice  games,  and  carried  out  coldly  calculated  street  executions."  New  York  "is  not 
alone.  Shootings  are  on  the  rise  in  other  big  cities  across  the  country,  including  Chicago  and  Minneapolis,  a  trend  that  some 
conservatives  have  seized  on  to  argue  against  the  recent  demands  of  protesters  to  cut  police  budgets  and  rein  in  officers."  On 
Monday,  Mayor  Bill  de  Blasio  "announced  that  the  city  was  sending  more  officers  into  the  streets  and  declared  he  would  not 
retreat  from  efforts  to  overhaul  the  Police  Department." 

Federal,  Local  Authorities  Arrest  14  Suspects  In  South  Carolina  Car-Jacking,  Drug  Ring 

The  Columbia  (SC)  State  (6/23,  Monk)  reports,  "More  than  200  federal  and  local  law  enforcement  officers  on  Tuesday 
rounded  up  14  members  of  an  alleged  Columbia-area  violent  gang  whose  members  specialized  in  carjackings,  armed  robberies 
and  drug  dealing."  According  to  US  Attorney  Peter  McCoy,  who  announced  the  arrests  Tuesday,  the  arrests  "were  the  result  of 
a  nearly  two-year  investigation  by  the  FBI,  the  DEA  and  local  law  enforcement  into  a  spike  in  gang-related  violence  in  Richland, 
Lexington  and  Kershaw  counties  that  began  in  July  2018."  FBI  South  Carolina  SAC  Jody  Norris  said,  "Even  in  the  midst  of  a 
pandemic,  the  FBI  and  its  task  forces  will  continue  to  find  and  arrest  drug  traffickers  who  work  against  the  people  of  South 
Carolina."  Also  reporting  are  WACH-TV  HHcolumbia,  SC  (6/23,  Lanahan)  and  WIS-TV  HBcolumbia,  SC  (6/23,  Greene). 

GLOBAL  SECURITY 


Suicide  Bomber  Targets  Turkish  Military  Base  In  Somalia 

The  New  York  Times  (6/23,  Mohamed,  Dahir)  reports,  "Two  people  were  killed  after  a  suicide  bomber  detonated  his 
explosives  outside  Turkey's  largest  overseas  military  base  in  Mogadishu  on  Tuesday."  The  attack,  which  the  Times  says  "bears 
the  hallmarks  of  the  Shabab  terrorist  group,  was  carried  out  just  before  9  a.m.  as  recruits  lined  up  for  enlistment  at  Camp 
Turksom,  where  hundreds  of  Somali  soldiers  are  trained  and  the  new  enrollment  of  dozens  was  underway." 

The  AP  (6/23,  Guled)  says  Tuesday's  attack  marks  "the  first  time  Turkey's  largest  overseas  military  base  has  been 


attacked  by  the  al-Qaida-linked  al-Shabab  extremist  group/'  which  "quickly  claimed  responsibility,  according  to  its  Radio  al- 
Furqan  affiliate." 

Secret  Recordings  Detail  Neo-Nazi  Group's  Grooming,  Recruiting  Process 

Fox  News  (6/23,  Chakraborty)  reports  on  newly  revealed  secret  recordings,  first  reported  by  the  BBC,  which  show  "senior 
members  of  The  Base,  a  hate  group  started  in  the  United  States,  interviewing  young  applicants,  discussing  their  prospects  and 
ways  to  radicalize  them."  The  founder  of  the  group,  American  Rinaldo  Nazzaro,  "who  now  directs  members  of  his  group  from 
St.  Petersburg,  Russia,  is  heard  asking  prospective  members  about  their  ethnicity,  radicalization  journey  and  their  experience 
with  weapons."  Fox  reports  Nazzaro  "purportedly  worked  as  an  analyst  for  the  FBI  and  as  a  contractor  for  the  Pentagon  before 
he  left  New  York  for  Russia  less  than  two  years  ago." 

ALSO  IN  THE  NEWS 


FCC  To  Vote  Next  Month  On  Making  "988"  New  Suicide  Hotline  Number 

The  AP  (6/23,  Arbel)  reports  the  FCC  "will  vote  in  July  on  whether  to  make  '988'  the  number  to  reach  a  suicide  prevention 
hotline."  The  Commission  explained  that  "phone  service  providers  will  have  until  July  2022  to  implement  the  new  number,  if 
the  measure  is  approved  in  July,  as  expected." 
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Greetings  Sean  Gleason  Wednesday,  June  24,  2020 


POLICING  &  POLICY 


Top  Senate  Democrats  Dismiss  Republican  Policing 
Reform  Bill 

The  AP  (6/23,  Mascaro)  reports  Congress  is  "hitting  an  impasse  on 
aolicing  legislation,  as  key  Senate  Democrats  on  Tuesday  opposed  a 
Republican  proposal  as  inadequate,  leaving  the  parties  to  decide 
whether  to  take  on  the  hard  job  of  negotiating  a  compromise  or  walk 
away."  Ahead  of  a  test  vote  Wednesday,  Senate  Majority  Leader 
McConnell  "acknowledged  it  may  fall  short,"  and  the  GOP  bill's  author, 
sen.  Tim  Scott  (R-SC),  "warned  against  a  partisan,  political  debate  that 
chisels  away  confidence  in  the  nation's  institutions."  Reuters 
[6/23,  Morgan)  similarly  says  "Democrats  and  Republicans.. .found 
themselves  in  a  partisan  deadlock  on  Tuesday." 

AP-NORC  Poll:  Nearly  All  Americans  Back  Some  Kind  Of  Criminal  Justice  Reform.  The  AP  (6/23,  Long, 
Fingerhut)  reports  that  Americans  "overwhelmingly  want  clear  standards  on  when  police  officers  may  use  force  and 
consequences  for  officers  who  do  so  excessively,  according  to  a  new  poll  that  finds  nearly  all  Americans  favor  at  least  some 
level  of  change  to  the  nation's  criminal  justice  system."  The  new  AP-NORC  poll  "also  finds  there  is  strong  support  for  penalizing 
officers  who  engage  in  racially  biased  policing." 

Confronting  Nazi  Legacy  Part  Of  German  Police  Training 

The  New  York  Times  (6/23,  Bennhold,  Eddy)  reports  that  "visiting  a  former  concentration  camp  is  mandatory  for  every 
future  police  officer  in  Berlin."  To  the  Times,  it  is  "one  of  the  ways  in  which  policing  was  fundamentally  overhauled  in  Germany 
afterWorld  Warll." 

Rhode  Island  Governor  Signs  Ban  On  3D-Printed  Weapons,  "Ghost  Guns" 

The  AP  (6/23,  Pratt)  reports  that  Rhode  Island  Gov.  Gina  Raimondo  "on  Tuesday  signed  into  law  bills  that  ban  3D-printed 
guns  and  so-called  'ghost  guns'  in  the  state."  The  bills  "are  'a  matter  of  public  health,'  she  said."  The  bills  "were  approved  by 
the  legislature  last  week,"  and  "make  it  illegal  to  manufacture,  import,  sell,  ship,  deliver,  possess,  transfer  or  receive  any  such 
firearms.  Anyone  who  violates  the  ban  and  is  convicted  could  serve  up  to  10  years  in  prison  and  faces  fines  of  up  $10,000.  The 
laws  take  effect  in  30  days." 

Seattle,  Washington  To  End  Anti-Loitering  Law 

Fox  News  (6/23,  Carter)  reports,  "Seattle  is  moving  to  end  a  longstanding  city  law  that  allowed  police  to  arrest  someone 
for  loitering,  if  they  are  also  suspected  of  being  a  possible  drug  offender  or  sex  worker."  According  to  Fox  News,  "The  twin  bills, 
passed  unanimously  by  the  Seattle  City  Council  Monday,  effectively  block  authorities  from  arresting  someone  for  loitering  in 
relation  to  a  drug  or  a  prostitution  inquiry.  Both  laws,  according  to  the  Chicago-Kent  Law  Review,  have  historically  targeted 
people  of  color." 

Georgia  Lawmakers  Pass  Bills  On  Hate  Crimes,  Enhanced  Police  Protections 

The  AP  (6/23,  Nadler,  Amy)  reports,  "Georgia's  legislature  on  Tuesday  passed  hate  crimes  legislation  deemed  essential  by 
business  and  many  political  leaders,  sending  the  measure  to  Gov.  Brian  Kemp's  desk.  The  price  Republicans  exacted  for  moving 
that  legislation  forward  was  simultaneous  passage  of  a  separate  bill  that  would  mandate  penalties  for  crimes  targeting  police 
and  other  first  responders."  According  to  the  AP,  "The  action  comes  after  Senate  Republicans  had  added  police  as  a  protected 
class  to  the  hate  crimes  legislation  last  week  in  committee,  but  then  later  moved  those  protections  to  a  separate  bill  in  a  deal 
between  the  parties.  Democrats  on  Tuesday  voted  overwhelmingly  against  House  Bill  838,  which  includes  the  increased 
protections  for  first  responders.  The  hate  crimes  legislation,  House  Bill  426,  had  bipartisan  support." 
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their  families.  The  Line-of-Duty  Serious  Injury  Considerations  document  and  Concepts  &  Issues  paper  from  the 
IACP  Law  Enforcement  Policy  Center  provides  guidelines  for  agencies  to  consider. 
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CRIME  &  DRUGS 


Law  Enforcement  Concerned  About  Rash  Of  Gun-Store  Robberies 

Politico  (6/23,  Swan)  reports,  "A  rash  of  gun-store  burglaries  has  alarmed  law  enforcement  officials,  and  comes  amid 
widespread  protests  that  have  been  accompanied  by  incidents  of  looting  and  vandalism  across  the  country."  According  to 
Politico,  "In  the  last  days  of  May  and  first  week  of  June,  there  were  more  than  90  attempted  or  successful  burglaries  of  gun 
stores,  according  to  the  Bureau  of  Alcohol,  Tobacco,  and  Firearms  (ATF).  More  than  1,000  guns  were  stolen  in  that  window  of 
time,  the  bureau's  assistant  director  of  field  operations  Tom  Chittum  told  POLITICO.  'It's  a  lot  of  guns,'  Chittum  said  in  an 
interview.  'It's  the  biggest  spike  I  have  ever  seen  of  gun  store  burglaries.'"  Chittum  "said  investigations  into  the  surge  of  gun 
store  burglaries  are  underway,  and  that  some  of  the  burglaries  appeared  to  be  part  of  broader  looting.  Other  cases,  he  added, 
may  have  been  the  work  of  opportunists." 

Gun  Violence  Spikes  In  New  York  City 

The  New  York  Times  (6/23,  Southall,  Macfarquhar)  reports,  "It  has  been  nearly  a  quarter  century  since  New  York  City 
experienced  as  much  gun  violence  in  the  month  of  June  as  it  has  seen  this  year."  The  city  "logged  125  shootings  in  the  first 
three  weeks  of  the  month,  more  than  double  the  number  recorded  over  in  same  period  last  year,  police  data  show.  Gunmen 
opened  fire  during  house  parties,  barbecues,  dice  games,  and  carried  out  coldly  calculated  street  executions."  New  York  "is  not 
alone.  Shootings  are  on  the  rise  in  other  big  cities  across  the  country,  including  Chicago  and  Minneapolis,  a  trend  that  some 
conservatives  have  seized  on  to  argue  against  the  recent  demands  of  protesters  to  cut  police  budgets  and  rein  in  officers."  On 
Monday,  Mayor  Bill  de  Blasio  "announced  that  the  city  was  sending  more  officers  into  the  streets  and  declared  he  would  not 
retreat  from  efforts  to  overhaul  the  Police  Department." 

Federal,  Local  Authorities  Arrest  14  Suspects  In  South  Carolina  Car-Jacking,  Drug  Ring 

The  Columbia  (SC)  State  (6/23,  Monk)  reports,  "More  than  200  federal  and  local  law  enforcement  officers  on  Tuesday 
rounded  up  14  members  of  an  alleged  Columbia-area  violent  gang  whose  members  specialized  in  carjackings,  armed  robberies 
and  drug  dealing."  According  to  US  Attorney  Peter  McCoy,  who  announced  the  arrests  Tuesday,  the  arrests  "were  the  result  of 
a  nearly  two-year  investigation  by  the  FBI,  the  DEA  and  local  law  enforcement  into  a  spike  in  gang-related  violence  in  Richland, 
Lexington  and  Kershaw  counties  that  began  in  July  2018."  FBI  South  Carolina  SAC  Jody  Norris  said,  "Even  in  the  midst  of  a 
pandemic,  the  FBI  and  its  task  forces  will  continue  to  find  and  arrest  drug  traffickers  who  work  against  the  people  of  South 
Carolina."  Also  reporting  are  WACH-TV  HHcolumbia,  SC  (6/23,  Lanahan)  and  WIS-TV  HBcolumbia,  SC  (6/23,  Greene). 

GLOBAL  SECURITY 


Suicide  Bomber  Targets  Turkish  Military  Base  In  Somalia 

The  New  York  Times  (6/23,  Mohamed,  Dahir)  reports,  "Two  people  were  killed  after  a  suicide  bomber  detonated  his 
explosives  outside  Turkey's  largest  overseas  military  base  in  Mogadishu  on  Tuesday."  The  attack,  which  the  Times  says  "bears 
the  hallmarks  of  the  Shabab  terrorist  group,  was  carried  out  just  before  9  a.m.  as  recruits  lined  up  for  enlistment  at  Camp 
Turksom,  where  hundreds  of  Somali  soldiers  are  trained  and  the  new  enrollment  of  dozens  was  underway." 

The  AP  (6/23,  Guled)  says  Tuesday's  attack  marks  "the  first  time  Turkey's  largest  overseas  military  base  has  been 


attacked  by  the  al-Qaida-linked  al-Shabab  extremist  group/'  which  "quickly  claimed  responsibility,  according  to  its  Radio  al- 
Furqan  affiliate." 

Secret  Recordings  Detail  Neo-Nazi  Group's  Grooming,  Recruiting  Process 

Fox  News  (6/23,  Chakraborty)  reports  on  newly  revealed  secret  recordings,  first  reported  by  the  BBC,  which  show  "senior 
members  of  The  Base,  a  hate  group  started  in  the  United  States,  interviewing  young  applicants,  discussing  their  prospects  and 
ways  to  radicalize  them."  The  founder  of  the  group,  American  Rinaldo  Nazzaro,  "who  now  directs  members  of  his  group  from 
St.  Petersburg,  Russia,  is  heard  asking  prospective  members  about  their  ethnicity,  radicalization  journey  and  their  experience 
with  weapons."  Fox  reports  Nazzaro  "purportedly  worked  as  an  analyst  for  the  FBI  and  as  a  contractor  for  the  Pentagon  before 
he  left  New  York  for  Russia  less  than  two  years  ago." 

ALSO  IN  THE  NEWS 


FCC  To  Vote  Next  Month  On  Making  "988"  New  Suicide  Hotline  Number 

The  AP  (6/23,  Arbel)  reports  the  FCC  "will  vote  in  July  on  whether  to  make  '988'  the  number  to  reach  a  suicide  prevention 
hotline."  The  Commission  explained  that  "phone  service  providers  will  have  until  July  2022  to  implement  the  new  number,  if 
the  measure  is  approved  in  July,  as  expected." 
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•  US  Supreme  Court  Will  Not  Revisit  Challenge  To  Qualified  Immunity  For  Police 

•  Swedish  Rape  Conviction  Rates  Rise  75%  After  Change  In  Law 

•  "Blueleaks"  Hackers  Release  "Hundreds  Of  Thousands"  Of  Private  Records  On  Officers 

•  NYTimes  Analysis:  Antifa  Rumors  Show  Ways  Information  Spreads  Locally 
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SPONSORED  BY  RECORDED  FUTURE: 

Get  real-time  security  intelligence  at  no  cost. 

We  recently  launched  Recorded  Future  Express  —  a  free  browser  extension  for  security 
teams.  Use  Express  over  any  web-based  SIEM,  vulnerability  management  solution,  security 
blog,  and  more  to  put  real-time  security  intelligence  at  your  fingertips.  Instantly  prioritize 
alerts,  incidents,  and  vulnerabilities  based  on  real-time  risk  scores  from  the  world’s  largest 
commercial  collection  platform.  Sign  up  now. 


Daily  briefing. 

June  24,  2020. 


SUMMARY 


By  the  CyberWire  staff 

Twitter  tojd  ZDNet  that  the  social  network  has  permanently  suspended  the  @DDoSecrets 


Twitter  account,  an  account  belonging  to  the  group  responsible  for  BlueLeaks,  because 
DDoSecrets  violated  Twitter's  policy  against  distribution  of  hacked  material. 

ReversingLabs  offers  a  walk  through  the  tools  North  Korea's  Hidden  Cobra  (also  known  as 
the  Lazarus  Group)  uses.  The  lesson  the  researchers  draw  is  that  it's  possible  to  develop  a 
rich  picture  of  a  threat  actor  from  a  starting  point  of  publicly  available  intelligence. 

Channel  News  writes  that  Beijing  is  expected  to  retaliate  for  Canberra's  strong  hint  that 
Chinese  intelligence  services  are  hacking  targets  in  Australia  on  a  large  scale.  The  response 
is  expected  to  take  the  form  of  tariffs  and  bans  on  certain  Australian  exports. 

The  Washington  Post  calls  Kentucky's  primary  elections  yesterday  a  success  story  worthy  of 
emulation. 

A  lot  of  people,  during  the  lockdowns  and  stay-at-home  plans  that  many  jurisdictions  have 
imposed  or  recommended  during  the  pandemic,  have  turned  to  indoor  amusement  to  pass 
the  time.  Like  watching  far  too  much  television,  and  that's  true  not  only  in  the  larger  world,  but 
in  the  underworld  as  well.  Digital  Shadows  has  noticed  an  interesting  development  in  the 
anglophone  cybercriminal  platform  Nulled:  its  gangland  proprietors  have  begun  offering  a 
livestreaming  service,  "Nulledflix,"  to  its  members.  The  service  offers  television,  "blockbuster" 
movies,  and  various  "memes."  It  comes  with  a  chat  feature  through  which  members  can 
exchange  tips,  comments,  and  so  forth.  The  point  seems  to  be  building  underworld  brand 
loyalty.  And  even  criminals  like  to  binge-watch  T.V. 
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SPONSORED  BY  GDIT: 

Secure  your  mission  with  the  GDIT  Cyber  Stack,  our  ecosystem  of  cyber 

capabilities. 


Notes. 

Today's  issue  includes  events  affecting  Australia,  Austria,  Brazil,  China,  Germany,  India, 
Ireland,  the  Democratic  People's  Republic  of  Korea,  New  Zealand,  Switzerland,  the  United 
Kingdom,  and  the  United  States. 

Word  Notes  Wednesday:  DevSecOps 

DevSecOps  (noun).  Development  Security  Operations.  The  collapsing  of  traditional  IT 
operations,  code  deployment  operations,  and  security  operations,  into  a  single  and  cohesive 
system  of  systems  that  delivers  infrastructure  as  code. 


SPONSORED  BY  MCAFEE: 


Transition  your  enterprise  to  a  secured,  remote  work  environment 


with  McAfee 


Most  companies  aren’t  prepared  to  secure  data  and  assets  for  a  surge  of  remote  employees. 
Whether  your  VPN  is  over  capacity,  new  cloud  services  are  coming  on-board,  or  new  devices 
need  protection,  we  have  you  covered  during  this  critical  time.  McAfee  is  offering  3-month 
subscriptions  for  Endpoint  Protection,  Unified  Cloud  Edge,  and  CASB  to  help  you  scale 
security  to  your  remote  employees.  Learn  more  about  these  offers 
at  mcafee.com/workfromhome. 


ON  THE  PODCAST 


In  today's  CvberWire  Daily  Podcast,  out  later  this  afternoon,  we  speak  with  our  partners  at  the 
Johns  Hopkins  University's  Information  Security  Institute,  as  Joe  Carriqan  discusses  the 
Ripple20  vulnerabilities.  Our  guest,  as  we  continue  Canon  Week,  is  Joseph  Menn,  author  of 
Cult  of  the  Dead  Cow:  How  the  Original  Hacking  Supergroup  Might  Just  Save  the  World. 

And  Caveat  is  also  up.  In  this  episode,  "Code  is  law."  Dave's  got  the  story  of  how  the  FBI 
used  open  source  intelligence  to  track  down  an  alleged  arsonist,  Ben  describes  a  facial 
recognition  test  that  took  place  at  the  Rose  Bowl,  and  later  in  the  show  our  conversation  with 
Maureen  Webb  on  her  forthcoming  book,  Coding  Democracy:  How  Hackers  Are  Disrupting 
Power,  Sun/eillance,  and  Authoritarianism. 


SPONSORED  EVENTS 


Cyber  Security  Summit  Virtual  Power  Hours  (Online,  June  23  -  25,  2020)  Senior  Level 
Executives  are  invited  to  the  Cyber  Summit  Virtual  Power  Hours.  Learn  from  Industry  Experts 
from  The  FBI,  DHS,  U.S.  Secret  Service  &  leading  cyber  solution  providers  as  they  discuss 
the  latest  security  challenges  &  develop  cyber  security  battle  plans  in  today’s  unprecedented 
times.  You  will  receive  1  CPE  /  CEU  credit  by  attending.  Free  to  register  with  code: 
CyberWire20  at  CyberSummitUSA.com. 

Improving  Cvber-Oriented  Education  (Online,  June  25,  2020)  The  Cyberspace  Solarium 
Commission  (CSC)  recently  released  a  report  that  proposes  a  strategy  of  layered  cyber 
deterrence.  Tune  in  to  hear  from  CSC  Commissioners  and  Industry  leaders  to  discuss  the 
report’s  findings,  educational  aspects,  and  opportunities  to  improve  Cyber-oriented  education. 

FutureCon  Virtual  Eastern  Conference  (Online,  June  30,  2020)  This  virtual  event  features 
thought-provoking  presentations  by  Industry  Security  Leaders,  esteemed  Keynote  Speakers, 
and  a  Panel  Session  discussion  with  experienced  professionals  and  a  talented  team  who  are 
at  the  forefront  of  cutting  edge  strategies  for  Cybersecurity  defense.  100%  off  promo  code: 
CYBERWIRE 

loT  Integrator  Summit:  Securing  Edge  Computing  (Online,  July  1 4  -  1 6,  2020)  A  virtual 
summit  to  help  loT  Integrators  learn  more  about  advances  and  updates  in  loT  security  and 
discover  new  methods  for  architecting  loT  solutions  for  your  organization  or  your  clients. 


RSA  Conference  APJ  July  15-17,  2020  -  A  Virtual  Learning  Experience  (Online,  July  15  - 
17,  2020)  The  world’s  leading  cybersecurity  event  is  going  virtual  15-17  July.  Join  your  peers 
and  industry  experts  for  three  days  of  insights.  Watch  over  50  sessions  live  during  Singapore 
business  hours — or  stream  them  later.  Register  today  for  free. 


SELECTED  READING 


Cyber  Attacks,  Threats,  and  Vulnerabilities 

Hidden  Cobra  -  from  a  shed  skin  to  the  viper’s  nest  (ReversingLabs)  Enriching  public 
threat  intelligence 

Twitter  bans  DDoSecrets  account  over  'BlueLeaks'  police  data  dump  7DNet)  Twitter 
said  DDoSecrets  account  leaked  and  promoted  BlueLeaks,  a  huge  collection  of  files  stolen 
from... 

SixLittleMonkeys  Malware  Resurfaces  with  with  API-like  Programming  Enhancements 

(MSSP  Alert)  SixLittleMonkeys,  an  advanced  persistent  threat  (APT)  actor,  applies  API  -style 
coding  to  its  malware,... 

Find  MORE  on  our  website. 


Security  Patches,  Mitigations,  and  Software  Updates 

Windows  10's  Mail  app  is  deleting  Gmail  users'  emails  (BetaNews)  An  update  from  last 
month  seems  to  have  introduced  a  bug  into  the  Mail  app  which  is  causing  problems... 

Cyber  Trends 

The  Cost  of  Privacy  Report  2020  (Okta)  Reporting  on  the  State  of  Digital  Identity  in  2020. 

The  Indelible  Impact  of  COVID-19  on  Cybersecurity  (Bitdefender)  Half  of  infosec 
professionals  (50%)  revealed  that  their  organisations  didn’t  have  a  contingency  plan... 

Internet  Security  Report  -  Q1  2020  (WatchGuard  Technologies)  The  Threat  Lab  team 
analyzes  data  from  WatchGuard’s  Firebox  Feed,  internal  and  partner  threat  intelligence,... 

Find  MORE  on  our  website. 

Marketplace 

WSJ  News  Exclusive  I  Dell  Explores  Spinoff  of  $50  Billion  Stake  in  VMware  (Wall  Street 

Journal)  Dell  is  considering  a  spinoff  and  other  options  for  its  stake  in  the  cloud-software 
giant,  as  the  PC... 

SecurityGate.io  announces  Series  A  funding  with  Houston  Ventures  for  accelerating 

innovation  to  transform  cybersecurity  management  in  OT/ICS  operational 
environments  (PR  Newswire)  SecurityGate.io,  a  cybersecurity  software  company  that  helps 


organizations  become  leaders  and  experts... 


Atos  to  acquire  Paladion  (ETCIO.com)  This  acquisition  will  bring  Managed  Detection  and 
Response  capabilities  to  the  Atos  portfolio. 

Find  MORE  on  our  website. 

Products,  Services,  and  Solutions 

YouAttest  Launches  First  Cloud-Based  Identity  Auditing  and  Compliance  Solution  for 

Okta's  Identity  Cloud  (PR  Newswire)  YouAttest,  an  innovator  in  the  Identity  Governance  & 
Administration  (IGA)  market  today  announced  the... 

Armis  Launches  New  Global  Reseller  Channel  Program  (PR  Newswire)  Armis®,  the 
leading  enterprise  loT  security  company,  today  announced  the  Armis  Reseller  Channel 
(ARC)... 

ZL  Technologies  Solves  Compliance  Challenges  for  Financial  Institutions  with 

Advancements  to  its  Platform  (GlobeNewswire)  New  offering  leverages  powerful  lexical 
engine  and  ML  models  to  provide  compliance  departments  with  better... 

Find  MORE  on  our  website. 

Technologies,  Techniques,  and  Standards 

Cloud  misconfiqurations  and  security:  5  wavs  to  avoid  your  next  fail  (TechBeacon) 
Here's  how  to  securely  configure  your  cloud  services  and  keep  them  safe. 

HITRUST  Releases  Version  9.4  of  the  HITRUST  CSF  Incorporating  the  DoD  CMMC,  and 

Approach  to  Community  Standards  (HITRUST)  Latest  release  of  the  HITRUST  CSF 
furthers  benefits  towards  One  Framework,  One  Assessment,  Globally™ 

Forcepoint  Makes  the  Case  for  the  Future  of  Cloud-Powered  Cybersecuritv 

(TechSpective)  Forcepoint  is  hosting  the  SASE  CyberSummit  today.  SASE  is  an  acronym  for 
Secure  Access  Service  Edge — essentially... 

Find  MORE  on  our  website. 

Design  and  Innovation 

The  US  Intel  Community  Is  Being  Disrupted  (Defense  One)  Intelligence  agencies  aren’t 
businesses,  but  they'd  better  learn  from  private-sector  giants  gone  by. 

Korean  IT  firms  employ  Al  to  maintain  decorum  in  cyberspace  (Pulse)  The  Korean  IT 
names  have  employed  artificial  intelligence  (Al)  programs  to  oversee  decorum  in  online... 

Academia 

Illinois  Cyber  Security  Scholars  Program  (ICSSP)  (University  of  Illinois)  The  Information 
Trust  Institute  (ITI)  at  the  University  of  Illinois  at  Urbana-Champaign  is  an  interdisciplinary... 

Legislation,  Policy,  and  Regulation 


European  Authorities  Aim  to  Make  National  Coronavirus  Apps  Work  Across  Borders 

(Wall  Street  Journal)  The  European  Union  is  rushing  to  figure  out  how  it  can  make  national 
coronavirus  contact-tracing  apps... 

The  Fait  Accompli  and  Persistent  Engagement  in  Cyberspace  (War  on  the  Rocks  The 
Democratic  People’s  Republic  of  Korea  has  illicitly  generated  $2  billion  to  upgrade  its 
weapons  of... 

China  Hits  Back  At  Cyberattack  Claims  (Channel  News)  China  is  expected  to  come  down 
heavily  on  Australian  exports  as  tensions  heat  up  over  claims  it  was  responsible... 

Find  MORE  on  our  website. 

Litigation,  Investigation,  and  Law  Enforcement 

Germany  Can  Enforce  Facebook  Data  Collection  Order  (Law360)  Germany's  high  court 
has  dealt  Facebook  a  blow  in  a  landmark  case  that  connects  privacy  and  antitrust... 

Full  9th  Circ.  Won't  Reconsider  Facebook  Wiretap  Ruling  (Law360)  The  full  Ninth  Circuit 
on  Tuesday  shot  down  Facebook's  request  to  reconsider  a  panel's  ruling  that  users... 

Probes  Done,  No  Rulings  In  Irish  Facebook.  WhatsApp  Cases  (Law360)  Ireland's  data 
protection  watchdog  said  Tuesday  that  it  had  finished  probes  into  both  Facebook  and  its... 

Find  MORE  on  our  website. 


INDUSTRY  EVENTS 


For  a  complete  running  list  of  events,  please  visit  the  Event  Tracker  on  the  CyberWire 
website. 

Upcoming  Events 

WSIS  Forum  2020  (Online,  June  22  -  September  1 0,  2020)  The  World  Summit  on  the 
Information  Society  (WSIS)  Forum  2020,  celebrates  15  years  of  providing  a  multi¬ 
stakeholder... 

Hardware  Hacking  Virtual  Conference  (Online,  June  24,  2020)  Join  the  ioXt  Alliance  and 
register  now  for  our  upcoming  Summer  Virtual  Conference.  You’ll  hear  the  latest... 

Protecting  Your  Digital  Reality  (Online,  June  24,  2020)  The  COVID-19  pandemic  has 
heightened  the  cybersecurity  risks  for  everyone,  including  large  companies,... 

Texas  Cyber  June’gle  Virtual  Summit  (Online,  June  27  -  28,  2020)  The  Texas  Cyber 
June’gle  Virtual  Summit  is  June  27th  and  June  28th,  it  runs  approximately  30  hours  straight,... 

FutureCon  Virtual  Eastern  Conference  (Online,  June  30,  2020)  This  virtual  event  features 
thought-provoking  presentations  by  Industry  Security  Leaders,  esteemed  Keynote... 
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RE:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers 
Affected  by  #BlueLeaks  Data  Breach  -  TLP:  AMBER 


From: 

To: 


Sent: 

Received: 

Attachments: 


Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

Jonathan  Springborn  (Sheriff)  <Jonathan.Springborn@cookcountyil.gov>, 
Patrick  Kelly  (Sheriff)  <Patrick.Kelly@cookcountyil.gov>,  Christopher  Moore 
(Sheriff)  <Christopher.Moore@cookcountyil.gov> 

June  24,  2020  12:33:01  PM  CDT 
June  24,  2020  12:33:04  PM  CDT 

RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


See  attached  from  the  data  breach 


From:  Jonathan  Springborn  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  4:28  PM 

To:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov>;  Patrick  Kelly  (Sheriff) 
<Patrick.Kelly@cookcountyil.gov>;  Christopher  Moore  (Sheriff)  <Christopher.Moore@cookcountyil.gov> 

Subject:  FW:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data 
Breach -TLP:  AMBER 
Importance:  High 


FYI, 

You  may  want  to  check  out  this  alert  and  URL. 

Data  breach  affected:  Illinois  Crime  Reporting  and  Information  -  Metro  East 
https://www.bleepingcomputer.com/news/securitv/blueleaks-data-dump-exposes-over-24-years-of-police-records/ 


Jonathan  Springborn 
Jonathan.Springbom@cookcountyil.gov 

(773)674-6850 -Helpdesk 
(773)674-7762  -  Office  Desk  Phone 
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To:  Michael  Aliperti  <Michael.Aliperti@cisecurity.org>:  Ben  Spear  <Ben.Spear@cisecuritv.org> 

Subject:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data 
Breach -TLP:  AMBER 


External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 

TLP:  AMBER 

TO:  All  MS-ISAC  Members  and  Partners 
DATE:  June  23,  2020 

SUBJECT:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data  Breach 


On  June  1 9,  2020,  a  Twitter  account  announced  the  leak  of  1 0  years  of  data  from  police  departments, 
fusion  centers,  and  other  law  enforcement-related  entities  currently  being  tracked  on  social  media  as 
#BlueLeaks.  According  to  the  National  Fusion  Center  Association  (NFCA),  the  leak  is  the  result  of  a 
compromise  at  a  third  party  web  hosting  company,  Netsential. 

The  Twitter  account  is  associated  with  Distributed  Denial  of  Secrets  (DDOS),  a  collective  known  for  posting 
leaked  or  exfiltrated  data.  The  post  included  a  link  to  a  Dark  Web  location  hosting  269GB  of  files  and 
emails  including  bulletins,  advisories,  and  guides. 

Upon  receiving  notification  of  this  data  breach,  the  MS-ISAC  has  confirmed  the  existence  of  the  dataset 
and  is  currently  working  to  analyze  the  specific  contents  of  the  data  along  with  our  federal,  state,  and  local 
partners.  At  this  time,  some  MS-ISAC  products  and  correspondence  have  been  identified  in  the  leaked  data 
due  to  the  nature  of  our  relationship  with  fusion  centers  and  law  enforcement  entities.  It  is  likely  that  cyber 
threat  actors  will  utilize  MS-ISAC  information  and/or  other  portions  of  the  data  dump  to  create  tailored 
phishing  campaigns  or  conduct  other  malicious  cyber  activity. 

Recommendations: 

•  Be  vigilant  for  new  waves  of  phishing  campaigns  spoofing  emails  or  products. 

•  Implement  Sender  Policy  Framework  (SPF),  Domain  Keys  Identified  Mail  (DKIM),  and 
Domain-Based  Message  Authentication  Reporting  and  Conformance  (DMARC),  which  will 
assist  in  ensuring  that  senders  are  unable  to  spoof  your  email  domain.  For  assistance  in 
implementing  these  controls,  see  the  Global  Cyber  Alliance’s  DMARC  Guide 
https://dmarcguide.globalcvberalliance.Org/#/. 

•  Ensure  anti-virus  software  is  up  to  date. 

•  Remind  users  not  to  visit  un-trusted  websites  or  follow  links  provided  by  unknown  or  un¬ 
trusted  sources. 

•  Apply  the  Principle  of  Least  Privilege  to  all  systems  and  services. 

The  MS-ISAC  continues  to  monitor  this  situation  closely  and  will  release  further  information  as  appropriate. 

24x7  Security  Operations  Center 

Multi-State  Information  Sharing  and  Analysis  Center  (MS-ISAC) 

Elections  Infrastructure  Information  Sharing  and  Analysis  Center  (EI-ISAC) 

31  Tech  Valley  Drive 
East  Greenbush,  NY  12061 
SOC@cisecuritv.org  -  1-866-787-4722 

®  MS-ISAC’  £  Infrastructure 

1SAC 

oooo 


TLP:  AMBER 

Limited  Disclosure,  restricted  to  participants'  organizations.  Recipients  may  only  share  TLP: 
AMBER  information  with  members  of  their  own  organization,  and  with  clients  or  customers  who 
need  to  know  the  information  to  protect  themselves  or  prevent  further  harm. 

http://www.us-cert.gov/tlp/ 

This  message  and  attachments  may  contain  confidential  information.  If  it  appears  that  this  message  was  sent  to  you 
by  mistake,  any  retention,  dissemination,  distribution  or  copying  of  this  message  and  attachments  is  strictly 
prohibited.  Please  notify  the  sender  immediately  and  permanently  delete  the  message  and  any  attachments. 


Sorry  Late  Again! 


From: 


To: 

Sent: 

Received: 

Attachments: 


Keith  Morrison  (Sheriff)  </0=EXCHANGELABS/OU=EXCHANGE  ADMINISTRATIVE 
GROUP 

(FYDIBOHF23SPDLT)/CN=RECIPIENTS/CN=D2EBEC5431A14B10A53942341  DBD54F 
4-KEITH  MORRI> 

Donna  Fitzpatrick  (Sheriff)  <Donna. Fitzpatrick@cookcountyil.gov> 

June  24,  2020  12:41:31  PM  CDT 
June  24,  2020  12:41:00  PM  CDT 

David  Gray.xlsx,  Patrick  Kelly .xlsx,  Betty  Flarris.xlsx,  John  Witulski.xlsx,  Jonathan 
Springborn.xlsx 


Keith  Morrison 

Chief  Information  Security  Officer 
Cook  County  Sheriff’s  Office 
Bureau  of  Information  and  Technology 
Cook  County  Sheriff’s  Office 

(773)  674-8117 


RE:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers 
Affected  by  #BlueLeaks  Data  Breach  -  TLP:  AMBER 

To:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov>,  Jonathan 

Springborn  (Sheriff)  <Jonathan.Springborn@cookcountyil.gov>,  Christopher 
Moore  (Sheriff)  <Christopher.Moore@cookcountyil.gov> 

Sent:  June  24,  2020  12:41:43  PM  CDT 

Received:  June  24,  2020  12:41:32  PM  CDT 

Perfect! 


From:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

Sent:  Wednesday,  June  24,  2020  12:33  PM 

To:  Jonathan  Springborn  (Sheriff)  <Jonathan.Springborn@cookcountyil.gov>;  Patrick  Kelly  (Sheriff) 
<Patrick.Kelly@cookcountyil.gov>;  Christopher  Moore  (Sheriff)  <Christopher.Moore@cookcountyil.gov> 

Subject:  RE:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data 
Breach -TLP:  AMBER 


See  attached  from  the  data  breach 


From:  Jonathan  Springborn  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  4:28  PM 

To:  Keith  Morrison  (Sheriff)  <Keith.  Morrison@cookcountvil.gov>;  Patrick  Kelly  (Sheriff) 
<Patrick.Kellv@cookcountyil.gov>:  Christopher  Moore  (Sheriff)  <Christopher.Moore@cookcountyil.gov> 

Subject:  FW:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data 
Breach -TLP:  AMBER 
Importance:  High 

FYI, 

You  may  want  to  check  out  this  alert  and  URL. 


Data  breach  affected:  Illinois  Crime  Reporting  and  Information  -  Metro  East 


https://www.bleepingcomputer.com/news/securitv/blueleaks-data-dump-exposes-over-24-years-of-police-records/ 


Jonathan  Springborn 
Jonathan.Springborn@cookcountyil.gov 

(773)674-6850 -Helpdesk 
(773)674-7762  -  Office  Desk  Phone 


From:  MS-ISAC  Advisory  <MS-ISAC.Advisory@msisac.org> 

Sent:  Tuesday,  June  23,  2020  11:04  AM 

To:  Michael  Aliperti  <MichaeLAIiperti@cisecurity.org>:  Ben  Spear  <Ben.Spear@cisecurity.org> 

Subject:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data 
Breach -TLP:  AMBER 


External  Message  Disclaimer 


This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 

TLP:  AMBER 


TO:  All  MS-ISAC  Members  and  Partners 
DATE:  June  23,  2020 

SUBJECT:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data  Breach 

On  June  1 9,  2020,  a  Twitter  account  announced  the  leak  of  1 0  years  of  data  from  police  departments, 
fusion  centers,  and  other  law  enforcement-related  entities  currently  being  tracked  on  social  media  as 
#BlueLeaks.  According  to  the  National  Fusion  Center  Association  (NFCA),  the  leak  is  the  result  of  a 
compromise  at  a  third  party  web  hosting  company,  Netsential. 

The  Twitter  account  is  associated  with  Distributed  Denial  of  Secrets  (DDOS),  a  collective  known  for  posting 
leaked  or  exfiltrated  data.  The  post  included  a  link  to  a  Dark  Web  location  hosting  269GB  of  files  and 
emails  including  bulletins,  advisories,  and  guides. 

Upon  receiving  notification  of  this  data  breach,  the  MS-ISAC  has  confirmed  the  existence  of  the  dataset 
and  is  currently  working  to  analyze  the  specific  contents  of  the  data  along  with  our  federal,  state,  and  local 
partners.  At  this  time,  some  MS-ISAC  products  and  correspondence  have  been  identified  in  the  leaked  data 
due  to  the  nature  of  our  relationship  with  fusion  centers  and  law  enforcement  entities.  It  is  likely  that  cyber 
threat  actors  will  utilize  MS-ISAC  information  and/or  other  portions  of  the  data  dump  to  create  tailored 
phishing  campaigns  or  conduct  other  malicious  cyber  activity. 

Recommendations: 

•  Be  vigilant  for  new  waves  of  phishing  campaigns  spoofing  emails  or  products. 

•  Implement  Sender  Policy  Framework  (SPF),  Domain  Keys  Identified  Mail  (DKIM),  and  Domain- 
Based  Message  Authentication  Reporting  and  Conformance  (DMARC),  which  will  assist  in  ensuring 
that  senders  are  unable  to  spoof  your  email  domain.  For  assistance  in  implementing  these  controls, 
see  the  Global  Cyber  Alliance’s  DMARC  Guide  https://dmarcquide.qlobalcvberalliance.Org/#/. 

•  Ensure  anti-virus  software  is  up  to  date. 

•  Remind  users  not  to  visit  un-trusted  websites  or  follow  links  provided  by  unknown  or  un-trusted 
sources. 

•  Apply  the  Principle  of  Least  Privilege  to  all  systems  and  services. 

The  MS-ISAC  continues  to  monitor  this  situation  closely  and  will  release  further  information  as  appropriate. 
24x7  Security  Operations  Center 

Multi-State  Information  Sharing  and  Analysis  Center  (MS-ISAC) 

Elections  Infrastructure  Information  Sharing  and  Analysis  Center  (EI-ISAC) 

31  Tech  Valley  Drive 
East  Greenbush,  NY  12061 
SOC@cisecuritv.org  -  1-866-787-4722 

©  MS-ISAC  infrastructure 

1SAC 

oooo 


TLP:  AMBER 

Limited  Disclosure,  restricted  to  participants'  organizations.  Recipients  may  only  share  TLP: 
AMBER  information  with  members  of  their  own  organization,  and  with  clients  or  customers  who 


need  to  know  the  information  to  protect  themselves  or  prevent  further  harm. 
http://www.us-cert.gov/tlp/ 


This  message  and  attachments  may  contain  confidential  information.  If  it  appears  that  this  message  was  sent  to  you 
by  mistake,  any  retention,  dissemination,  distribution  or  copying  of  this  message  and  attachments  is  strictly 
prohibited.  Please  notify  the  sender  immediately  and  permanently  delete  the  message  and  any  attachments. 


RE:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers 
Affected  by  #BlueLeaks  Data  Breach  -  TLP:  AMBER 

To:  Keith  Morrison  (Sheriff),  Jonathan  Springborn  (Sheriff),  Christopher  Moore  (Sheriff) 

Sent:  June  24,  2020  12:41 :43  PM  CDT 

Received:  June  24,  2020  12:41 :32  PM  CDT 


FYI 


From: 


Keith  Morrison  (Sheriff)  </0=EXCHANGELABS/OU=EXCHANGE  ADMINISTRATIVE 
GROUP 

(FYDIBOHF23SPDLT)/CN=RECIPIENTS/CN=D2EBEC5431A14B10A53942341  DBD54F 
4-KEITH  MORRI> 


To: 

Sent: 

Received: 


CCSO  Intel  (Sheriff)  <CCSO.INTEL@cookcountyil.gov> 
June  24,  2020  12:43:14  PM  CDT 
June  24,  2020  12:43:00  PM  CDT 


Just  a  FYI  there  was  a  data  leak  of  officer  data  down  in  Houston 

https://www.theblaze.com/news/blueleaks-hackers-release-countless-records-on-police-officers-all-searchable-by- 

badge-number 


Additional  article  here 


Keith  Morrison 

Chief  Information  Security  Officer 
Cook  County  Sheriff’s  Office 
Bureau  of  Information  and  Technology 
Cook  County  Sheriff’s  Office 

(773)  674-8117 


FW:  FYI 


To: 

Sent: 

Received: 


Sheriff  Intel 

June  24,  2020  12:43:15  PM  CDT 
June  24,  2020  12:43:18  PM  CDT 


FW:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


To:  Michael.Tomasiello  (Chicago  Police)  <Michael. Tomasiello@chicagopolice.org> 

Sent:  June  24,  2020  12:45:16  PM  CDT 

Received:  June  24,  2020  12:45:12  PM  CDT 

I  hope  all  is  well  with  you  and  yours...  You  free  for  a  quick  call? 

773-674-8117 


From:  Amar  Patel  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  8:53  PM 

To:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

Cc:  Adnan  Memon  (Sheriff)  <Adnan.Memon@cookcountyil.gov>;  Douglas  Maclean  (Sheriff) 
<Douglas.Maclean2@cookcountyil.gov> 

Subject:  Re:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 
Hi  Keith, 

Is  our  Azure  data  center  affiliated  with  Netsential?  I  would  think  not,  but  can  we  verify.  Can  you  also  see  if 
CPD  (CPIC)  was  included  in  the  leak?  Intel  works  with  them  with  reports  and  officer  safety  bulletins.  I 
think  they  host  internally  or  on  AWS,  but  not  sure.  Thanks  sir. 


Thanks, 
Amar  Patel 


From:  Keith  Morrison  (Sheriff)  <Keith.  Morrison@cookcountvil.gov> 

Sent:  Tuesday,  June  23,  2020  7:10  AM 

Cc:  Amar  Patel  (Sheriff)  <Amar. Patel @cookcountvil.gov>;  Adnan  Memon  (Sheriff) 

<Adnan.  Memon@cookcountvil.gov>;  Douglas  Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov> 

Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

This  is  a  different  article  from  the  International  Association  of  Chiefs  of  Police  that  relates  Netsentinal  is  a  Houston 
service  provider  for  Law  Enforcement. 

https://www.theblaze.com/news/blueleaks-hackers-release-countless-records-on-police-officers-all-searchable-bv- 

badge-number 

I  think  our  only  risk  from  doxing  would  be  workforce.  I  pulled  the  attached  reports  last  Friday  and  provided  them  to 
Chuck  at  Homeland  for  review. 


From:  Douglas  Maclean  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:10  AM 

To:  Amar  Patel  (Sheriff)  <Amar. Patel@cookcountvil.gov>:  Keith  Morrison  (Sheriff) 

<Keith. Morrison@cookcountvil.gov>:  Adnan  Memon  (Sheriff)  <Adnan.Memon@cookcountyil.gov> 
Subject:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


Krebs  on  Security  reports  Blue  Leaks  has  posted  24  years  of  LEA  and  fusion  center-related  data  as  the  result  of  a 
breach  on  Netsential,  an  internet  services  provider  to  LEAs  and  operational  fusion  centers.  The  data  includes  some 
information  related  to  sensitive  operations  and  a  significant  amount  of  Pll. 

The  Krebs  on  Security  story  can  be  found  here 

Keith  -  do  we  have  any  exposure  from  this  breach  either  directly  from  our  own  infrastructure  or  indirectly  as  the 
result  of  data-sharing  with  other  agencies?  Do  any  of  our  vendors  use  or  have  they  used  Netsential  for  any  of  their 
operations  from  1994  to  present? 


Douglas  MacLean 
Deputy  CIO 

Cook  County  Sheriffs  Office 
3026  S.  California 
South  Campus  Building  1 
Chicago  IL  60608 
312.877.2048  [c] 
773.674.8615  [d] 


RE:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers 
Affected  by  #BlueLeaks  Data  Breach  -  TLP:  AMBER 

From:  Patrick  Kelly  (Sheriff)  <Patrick.Kelly@cookcountyil.gov> 

To:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov>,  Jonathan 

Springborn  (Sheriff)  <Jonathan.Springborn@cookcountyil.gov>,  Christopher 
Moore  (Sheriff)  <Christopher.Moore@cookcountyil.gov> 

Sent:  June  24,  2020  12:47:12  PM  CDT 

Received:  June  24,  2020  12:47:12  PM  CDT 

That's  great.  If  Chuck  and  his  team  didn't  realize  that  stuff  about  Workforce,  they  do  now! 


From:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

Sent:  Wednesday,  June  24,  2020  12:33  PM 

To:  Jonathan  Springborn  (Sheriff)  <Jonathan.Springborn@cookcountyil.gov>;  Patrick  Kelly  (Sheriff) 
<Patrick.Kelly@cookcountyil.gov>;  Christopher  Moore  (Sheriff)  <Christopher.Moore@cookcountyil.gov> 

Subject:  RE:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data 
Breach -TLP:  AMBER 


See  attached  from  the  data  breach 


From:  Jonathan  Springborn  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  4:28  PM 

To:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov>:  Patrick  Kelly  (Sheriff) 
<Patrick.Kellv@cookcountyil.gov>;  Christopher  Moore  (Sheriff)  <Christopher.Moore@cookcountyil.gov> 

Subject:  FW:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers  Affected  by#BlueLeaks  Data 
Breach -TLP:  AMBER 
Importance:  High 


FYI, 

You  may  want  to  check  out  this  alert  and  URL. 

Data  breach  affected:  Illinois  Crime  Reporting  and  Information  -  Metro  East 
https://www.bleepingcomputer.com/news/security/blueleaks-data-dump-exposes-over-24-vears-of-police-records/ 


Jonathan  Springborn 
Jonathan.Springborn@cookcountyil.gov 

(773)674-6850 -Helpdesk 
(773)674-7762  -  Office  Desk  Phone 


From:  MS-ISAC  Advisory  <MS-ISAC.Advisory@msisac.org> 

Sent:  Tuesday,  June  23,  2020  11:04  AM 

To:  Michael  Aliperti  <MichaeLAIiperti@dsecurity.org>:  Ben  Spear  <Ben.Spear@cisecurity.org> 

Subject:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data 
Breach -TLP:  AMBER 


External  Message  Disclaimer 


This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 

TLP:  AMBER 


TO:  All  MS-ISAC  Members  and  Partners 
DATE:  June  23,  2020 

SUBJECT:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data  Breach 

On  June  19,  2020,  a  Twitter  account  announced  the  leak  of  10  years  of  data  from  police  departments, 
fusion  centers,  and  other  law  enforcement-related  entities  currently  being  tracked  on  social  media  as 
#BlueLeaks.  According  to  the  National  Fusion  Center  Association  (NFCA),  the  leak  is  the  result  of  a 
compromise  at  a  third  party  web  hosting  company,  Netsential. 

The  Twitter  account  is  associated  with  Distributed  Denial  of  Secrets  (DDOS),  a  collective  known  for  posting 
leaked  or  exfiltrated  data.  The  post  included  a  link  to  a  Dark  Web  location  hosting  269GB  of  files  and 
emails  including  bulletins,  advisories,  and  guides. 

Upon  receiving  notification  of  this  data  breach,  the  MS-ISAC  has  confirmed  the  existence  of  the  dataset 
and  is  currently  working  to  analyze  the  specific  contents  of  the  data  along  with  our  federal,  state,  and  local 
partners.  At  this  time,  some  MS-ISAC  products  and  correspondence  have  been  identified  in  the  leaked  data 
due  to  the  nature  of  our  relationship  with  fusion  centers  and  law  enforcement  entities.  It  is  likely  that  cyber 
threat  actors  will  utilize  MS-ISAC  information  and/or  other  portions  of  the  data  dump  to  create  tailored 
phishing  campaigns  or  conduct  other  malicious  cyber  activity. 

Recommendations: 

•  Be  vigilant  for  new  waves  of  phishing  campaigns  spoofing  emails  or  products. 

•  Implement  Sender  Policy  Framework  (SPF),  Domain  Keys  Identified  Mail  (DKIM),  and  Domain- 
Based  Message  Authentication  Reporting  and  Conformance  (DMARC),  which  will  assist  in  ensuring 
that  senders  are  unable  to  spoof  your  email  domain.  For  assistance  in  implementing  these  controls, 
see  the  Global  Cyber  Alliance’s  DMARC  Guide  https://dmarcquide.qlobalcvberalliance.Org/#/. 

•  Ensure  anti-virus  software  is  up  to  date. 

•  Remind  users  not  to  visit  un-trusted  websites  or  follow  links  provided  by  unknown  or  un-trusted 
sources. 

•  Apply  the  Principle  of  Least  Privilege  to  all  systems  and  services. 

The  MS-ISAC  continues  to  monitor  this  situation  closely  and  will  release  further  information  as  appropriate. 
24x7  Security  Operations  Center 

Multi-State  Information  Sharing  and  Analysis  Center  (MS-ISAC) 

Elections  Infrastructure  Information  Sharing  and  Analysis  Center  (EI-ISAC) 

31  Tech  Valley  Drive 
East  Greenbush,  NY  12061 
SOC@cisecuritv.org  -  1-866-787-4722 

®  MS-ISAC’  iSr  Infrastructure 

I  SAC 

oooo 


TLP:  AMBER 


Limited  Disclosure,  restricted  to  participants'  organizations.  Recipients  may  only  share  TLP: 
AMBER  information  with  members  of  their  own  organization,  and  with  clients  or  customers  who 
need  to  know  the  information  to  protect  themselves  or  prevent  further  harm. 

http://www.us-cert.gov/tlp/ 

This  message  and  attachments  may  contain  confidential  information.  If  it  appears  that  this  message  was  sent  to  you 
by  mistake,  any  retention,  dissemination,  distribution  or  copying  of  this  message  and  attachments  is  strictly 
prohibited.  Please  notify  the  sender  immediately  and  permanently  delete  the  message  and  any  attachments. 


RE:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers 
Affected  by  #BlueLeaks  Data  Breach  -  TLP:  AMBER 

From:  Patrick  Kelly  (Sheriff)  </0=EXCHANGELABS/OU=EXCHANGE  ADMINISTRATIVE 

GROUP 

(FYDIBOHF23SPDLT)/CN=RECIPIENTS/CN=873FFD393E8C44B79E707E6A1 056650 
A-PATRICK  KEL> 

To:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov>,  Jonathan  Springborn 

(Sheriff)  <Jonathan.Springborn@cookcountyil.gov>,  Christopher  Moore  (Sheriff) 
<Christopher.Moore@cookcountyil.gov> 

Sent:  June  24,  2020  12:47:12  PM  CDT 

Received:  June  24,  2020  12:47:00  PM  CDT 

That's  great.  If  Chuck  and  his  team  didn't  realize  that  stuff  about  Workforce,  they  do  now! 


From:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

Sent:  Wednesday,  June  24,  2020  12:33  PM 

To:  Jonathan  Springborn  (Sheriff)  <Jonathan.Springborn@cookcountyil.gov>;  Patrick  Kelly  (Sheriff) 
<Patrick.Kelly@cookcountyil.gov>;  Christopher  Moore  (Sheriff)  <Christopher.Moore@cookcountyil.gov> 

Subject:  RE:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data 
Breach -TLP:  AMBER 


See  attached  from  the  data  breach 


From:  Jonathan  Springborn  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  4:28  PM 

To:  Keith  Morrison  (Sheriff)  <Keith.  Morrison@cookcountvil.gov>;  Patrick  Kelly  (Sheriff) 
<Patrick.Kellv@cookcountyil.gov>;  Christopher  Moore  (Sheriff)  <Christopher.Moore@cookcountyil.gov> 

Subject:  FW:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data 
Breach -TLP:  AMBER 

Importance:  High 

FYI, 

You  may  want  to  check  out  this  alert  and  URL. 


Data  breach  affected:  Illinois  Crime  Reporting  and  Information  -  Metro  East 


https://www.bleepingcomputer.com/news/securitv/blueleaks-data-dump-exposes-over-24-years-of-police-records/ 


Jonathan  Springborn 
Jonathan.Springborn@cookcountyil.gov 

(773)674-6850 -Helpdesk 
(773)674-7762  -  Office  Desk  Phone 


From:  MS-ISAC  Advisory  <MS-ISAC.Advisory@msisac.org> 

Sent:  Tuesday,  June  23,  2020  11:04  AM 

To:  Michael  Aliperti  <Michael.Aliperti@cisecurity.org>;  Ben  Spear  <Ben.Spear@cisecurity.org> 

Subject:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data 
Breach -TLP:  AMBER 


External  Message  Disclaimer 


This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 

TLP:  AMBER 


TO:  All  MS-ISAC  Members  and  Partners 
DATE:  June  23,  2020 

SUBJECT:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data  Breach 

On  June  19,  2020,  a  Twitter  account  announced  the  leak  of  10  years  of  data  from  police  departments, 
fusion  centers,  and  other  law  enforcement-related  entities  currently  being  tracked  on  social  media  as 
#BlueLeaks.  According  to  the  National  Fusion  Center  Association  (NFCA),  the  leak  is  the  result  of  a 
compromise  at  a  third  party  web  hosting  company,  Netsential. 

The  Twitter  account  is  associated  with  Distributed  Denial  of  Secrets  (DDOS),  a  collective  known  for  posting 
leaked  or  exfiltrated  data.  The  post  included  a  link  to  a  Dark  Web  location  hosting  269GB  of  files  and 
emails  including  bulletins,  advisories,  and  guides. 

Upon  receiving  notification  of  this  data  breach,  the  MS-ISAC  has  confirmed  the  existence  of  the  dataset 
and  is  currently  working  to  analyze  the  specific  contents  of  the  data  along  with  our  federal,  state,  and  local 
partners.  At  this  time,  some  MS-ISAC  products  and  correspondence  have  been  identified  in  the  leaked  data 
due  to  the  nature  of  our  relationship  with  fusion  centers  and  law  enforcement  entities.  It  is  likely  that  cyber 
threat  actors  will  utilize  MS-ISAC  information  and/or  other  portions  of  the  data  dump  to  create  tailored 
phishing  campaigns  or  conduct  other  malicious  cyber  activity. 

Recommendations: 

•  Be  vigilant  for  new  waves  of  phishing  campaigns  spoofing  emails  or  products. 

•  Implement  Sender  Policy  Framework  (SPF),  Domain  Keys  Identified  Mail  (DKIM),  and  Domain- 
Based  Message  Authentication  Reporting  and  Conformance  (DMARC),  which  will  assist  in  ensuring 
that  senders  are  unable  to  spoof  your  email  domain.  For  assistance  in  implementing  these  controls, 
see  the  Global  Cyber  Alliance’s  DMARC  Guide  https://dmarcquide.qlobalcvberalliance.orci/#/. 

•  Ensure  anti-virus  software  is  up  to  date. 

•  Remind  users  not  to  visit  un-trusted  websites  or  follow  links  provided  by  unknown  or  un-trusted 
sources. 

•  Apply  the  Principle  of  Least  Privilege  to  all  systems  and  services. 

The  MS-ISAC  continues  to  monitor  this  situation  closely  and  will  release  further  information  as  appropriate. 
24x7  Security  Operations  Center 

Multi-State  Information  Sharing  and  Analysis  Center  (MS-ISAC) 

Elections  Infrastructure  Information  Sharing  and  Analysis  Center  (EI-ISAC) 

31  Tech  Valley  Drive 
East  Greenbush,  NY  12061 
SOC@cisecuritv.org  -  1-866-787-4722 

®  MS-ISAC-  -ft  infrastructure 

1SAC 

oooo 


TLP:  AMBER 


Limited  Disclosure,  restricted  to  participants'  organizations.  Recipients  may  only  share  TLP: 
AMBER  information  with  members  of  their  own  organization,  and  with  clients  or  customers  who 
need  to  know  the  information  to  protect  themselves  or  prevent  further  harm. 

http://www.us-cert.gov/tlp/ 

This  message  and  attachments  may  contain  confidential  information.  If  it  appears  that  this  message  was  sent  to  you 
by  mistake,  any  retention,  dissemination,  distribution  or  copying  of  this  message  and  attachments  is  strictly 
prohibited.  Please  notify  the  sender  immediately  and  permanently  delete  the  message  and  any  attachments. 


RE:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers 
Affected  by  #BlueLeaks  Data  Breach  -  TLP:  AMBER 

To:  Keith  Morrison  (Sheriff),  Jonathan  Springborn  (Sheriff),  Christopher  Moore  (Sheriff) 

Sent:  June  24,  2020  12:47:12  PM  CDT 

Received:  June  24,  2020  12:47:00  PM  CDT 


FW:  FYI 


From:  Amar  Patel  (Sheriff)  </0=EXCHANGELABS/OU=EXCHANGE  ADMINISTRATIVE 

GROUP 

(FYDIBOHF23SPDLT)/CN=RECIPIENTS/CN=1214EEE73F204F47A1BAE37F472A201 1 
-AMAR  PATEL> 


To:  Douglas  Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov> 

Sent:  June  24,  2020  12:51:13  PM  CDT 

Received:  June  24,  2020  12:51 :00  PM  CDT 


From:  CCSO  Intel  (Sheriff)  <CCSO.INTEL@cookcountyil.gov> 

Sent:  Wednesday,  June  24,  2020  12:43  PM 

To:  Sheriff  Intel  <sheriff.intel@cookcountyil.gov> 

Subject:  FW:  FYI 


From:  Keith  Morrison  (Sheriff) 

Sent:  Wednesday,  June  24,  2020  12:43:14  PM  (UTC-06:00)  Central  Time  (US  &  Canada) 

To:  CCSO  Intel  (Sheriff) 

Subject:  FYI 

Just  a  FYI  there  was  a  data  leak  of  officer  data  down  in  Flouston 

https://www.theblaze.com/news/blueleaks-hackers-release-countless-records-on-police-officers-all-searchable-by- 

badge-number 


Additional  article  here 


Keith  Morrison 

Chief  Information  Security  Officer 
Cook  County  Sheriff’s  Office 
Bureau  of  Information  and  Technology 
Cook  County  Sheriff’s  Office 

(773)  674-8117 


FW:  FYI 


To: 

Cc: 

Sent: 

Received: 


Douglas  Maclean  (Sheriff),  Keith  Morrison  (Sheriff),  Leo  Schmitz  (Sheriff),  Bradley 
Curry  (Sheriff),  Marlon  Parks  (Sheriff),  Brian  White  (Sheriff),  Arunas  Buntinas  (Sheriff), 
Tarry  Williams  (Sheriff) 

Adnan  Memon  (Sheriff),  Douglas  Maclean  (Sheriff) 

June  24,  2020  12:51 :13  PM  CDT 
June  24,  2020  12:51 :00  PM  CDT 


RE:  FYI 


From: 

To: 

Sent: 

Received 
Yes  sir. 

From:  Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov> 

Sent:  Wednesday,  June  24,  2020  12:51  PM 

To:  Douglas  Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov> 
Subject:  FW:  FYI 


Douglas  Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov> 
Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov> 

June  24,  2020  12:54:42  PM  CDT 
June  24,  2020  12:54:43  PM  CDT 


From:  CCSO  Intel  (Sheriff)  <CCSO.INTEL(5)cookcountvil.gov> 

Sent:  Wednesday,  June  24,  2020  12:43  PM 

To:  Sheriff  Intel  <sheriff.intel(S>cookcountvil.gov> 

Subject:  FW:  FYI 


From:  Keith  Morrison  (Sheriff) 

Sent:  Wednesday,  June  24,  2020  12:43:14  PM  (UTC-06:00)  Central  Time  (US  &  Canada) 

To:  CCSO  Intel  (Sheriff) 

Subject:  FYI 

Just  a  FYI  there  was  a  data  leak  of  officer  data  down  in  Flouston 

https://www.theblaze.com/news/blueleaks-hackers-release-countless-records-on-police-officers-all-searchable-by- 

badge-number 


Additional  article  here 


Keith  Morrison 

Chief  Information  Security  Officer 
Cook  County  Sheriff’s  Office 
Bureau  of  Information  and  Technology 
Cook  County  Sheriff’s  Office 

(773)  674-8117 


RE:  FYI 


From:  Douglas  Maclean  (Sheriff)  </0=EXCHANGELABS/OU=EXCHANGE  ADMINISTRATIVE 

GROUP 

(FYDIBOHF23SPDLT)/CN=RECIPIENTS/CN=20EA541 1 E8A349589C43587009EDD1  OF 
-DOUGLAS  MAC> 

To:  Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov> 

Sent:  June  24,  2020  12:54:42  PM  CDT 

Received:  June  24,  2020  12:54:00  PM  CDT 

Yes  sir. 


From:  Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov> 

Sent:  Wednesday,  June  24,  2020  12:51  PM 

To:  Douglas  Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov> 
Subject:  FW:  FYI 


From:  CCSO  Intel  (Sheriff)  <CCSO.INTEL(5)cookcountvil.gov> 

Sent:  Wednesday,  June  24,  2020  12:43  PM 

To:  Sheriff  Intel  <sheriff.intel@cookcountyil.gov> 

Subject:  FW:  FYI 


From:  Keith  Morrison  (Sheriff) 

Sent:  Wednesday,  June  24,  2020  12:43:14  PM  (UTC-06:00)  Central  Time  (US  &  Canada) 

To:  CCSO  Intel  (Sheriff) 

Subject:  FYI 

Just  a  FYI  there  was  a  data  leak  of  officer  data  down  in  Flouston 

https://www.theblaze.com/news/blueleaks-hackers-release-countless-records-on-police-officers-all-searchable-by- 

badge-number 


Additional  article  here 


Keith  Morrison 

Chief  Information  Security  Officer 
Cook  County  Sheriff’s  Office 
Bureau  of  Information  and  Technology 
Cook  County  Sheriff’s  Office 

(773)  674-8117 


RE:  FYI 


To: 

Sent: 

Received: 


Amar  Patel  (Sheriff),  Keith  Morrison  (Sheriff),  Adnan  Memon  (Sheriff) 
June  24,  2020  12:54:42  PM  CDT 
June  24,  2020  12:54:00  PM  CDT 


FW:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


From:  Keith  Morrison  (Sheriff)  </0=EXCHANGELABS/OU=EXCHANGE  ADMINISTRATIVE 

GROUP 

(FYDIBOHF23SPDLT)/CN=RECIPIENTS/CN=D2EBEC5431A14B10A53942341  DBD54F 
4-KEITH  MORRI> 

To:  Michael.Tomasiello  (Chicago  Police)  <Michael.Tomasiello@chicagopolice.org> 

Sent:  June  24,  2020  1 :1 6:00  PM  CDT 

Received:  June  24,  2020  1:15:00  PM  CDT 


I  hope  all  is  well  with  you  and  yours...  You  free  for  a  quick  call? 


773-674-8117 


From:  Amar  Patel  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  8:53  PM 

To:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

Cc:  Adnan  Memon  (Sheriff)  <Adnan.Memon@cookcountyil.gov>;  Douglas  Maclean  (Sheriff) 
<Douglas.Maclean2@cookcountyil.gov> 

Subject:  Re:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 
Hi  Keith, 

Is  our  Azure  data  center  affiliated  with  Netsential?  I  would  think  not,  but  can  we  verify.  Can  you  also  see  if 
CPD  (CPIC)  was  included  in  the  leak?  Intel  works  with  them  with  reports  and  officer  safety  bulletins.  I 
think  they  host  internally  or  on  AWS,  but  not  sure.  Thanks  sir. 


Thanks, 
Amar  Patel 


From:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

Sent:  Tuesday,  June  23,  2020  7:10  AM 

Cc:  Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov>:  Adnan  Memon  (Sheriff) 
<Adnan.Memon@cookcountyil.gov>:  Douglas  Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov> 

Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

This  is  a  different  article  from  the  International  Association  of  Chiefs  of  Police  that  relates  Netsentinal  is  a  Houston 
service  provider  for  Law  Enforcement. 

https://www.theblaze.com/news/blueleaks-hackers-release-countless-records-on-police-officers-all-searchable-by- 

badge-number 

I  think  our  only  risk  from  doxing  would  be  workforce.  I  pulled  the  attached  reports  last  Friday  and  provided  them  to 
Chuck  at  Homeland  for  review. 


From:  Douglas  Maclean  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:10  AM 

To:  Amar  Patel  (Sheriff)  <Amar. Patel@cookcountvil.gov>:  Keith  Morrison  (Sheriff) 


<Keith.Morrison@cookcountyil.gov>;  Adnan  Memon  (Sheriff)  <Adnan.Memon@cookcountyil.gov> 

Subject:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Krebs  on  Security  reports  Blue  Leaks  has  posted  24  years  of  LEA  and  fusion  center-related  data  as  the  result  of  a 
breach  on  Netsential,  an  internet  services  provider  to  LEAs  and  operational  fusion  centers.  The  data  includes  some 
information  related  to  sensitive  operations  and  a  significant  amount  of  Pll. 

The  Krebs  on  Security  story  can  be  found  here 

Keith  -  do  we  have  any  exposure  from  this  breach  either  directly  from  our  own  infrastructure  or  indirectly  as  the 
result  of  data-sharing  with  other  agencies?  Do  any  of  our  vendors  use  or  have  they  used  Netsential  for  any  of  their 
operations  from  1994  to  present? 


Douglas  MacLean 
Deputy  CIO 

Cook  County  Sheriffs  Office 
3026  S.  California 
South  Campus  Building  1 
Chicago  IL  60608 
312.877.2048  [c] 
773.674.8615  [d] 


No  Action  Needed 


From:  Wing,  Gregory  J.  (CG)  (FBI)  <gjwing@fbi.gov> 

To:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

Sent:  June  24,  2020  1 :52:02  PM  CDT 

Received:  June  24,  2020  1 :52:09  PM  CDT 


External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 


10-4.  Thanks 

On  Jun  24,  2020  1:50  PM,  "Keith  Morrison  (Sheriff)"  <Keith.Morrison@cookcountyil.gov>  wrote: 
I  hope  all  is  well  with  you  and  yours 

I  am  sure  you  already  know  this.... 

A  contractor  for  a  bunch  of  police  agencies  was  hacked  and  their  data  posted  down  in  Houston... 
https://krebsonsecuritv.com/2020/06/blueleaks-exposes-files-from-hundreds-of-police-departments/ 


he  worked  with  some  of  your  guys  down  there 

https://archives.fbi.gov/archives/about-us/partnerships  and  outreach/community  outreach/dcla/2011/houston-l 


RE:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers 
Affected  by  #BlueLeaks  Data  Breach  -  TLP:  AMBER 

From:  Jonathan  Springborn  (Sheriff)  <Jonathan. Springborn@cookcountyil.gov> 

To:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov>,  Patrick  Kelly 

(Sheriff)  <Patrick.Kelly@cookcountyil.gov>,  Christopher  Moore  (Sheriff) 
<Christopher.Moore@cookcountyil.gov> 

Sent:  June  24,  2020  2:02:23  PM  CDT 

Received:  June  24,  2020  2:02:24  PM  CDT 

Awesome! 

Glad  our  data  was  not  leaked. 

Springborn 

Jonathan  Springborn 
Jonathan.Springbom@cookcountyil.gov 

(773)674-6850 -Helpdesk 
(773)674-7762  -  Office  Desk  Phone 


From:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

Sent:  Wednesday,  June  24,  2020  12:33  PM 

To:  Jonathan  Springborn  (Sheriff)  <Jonathan.Springborn@cookcountyil.gov>;  Patrick  Kelly  (Sheriff) 
<Patrick.Kelly@cookcountyil.gov>;  Christopher  Moore  (Sheriff)  <Christopher.Moore@cookcountyil.gov> 

Subject:  RE:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data 
Breach -TLP:  AMBER 


See  attached  from  the  data  breach 


From:  Jonathan  Springborn  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  4:28  PM 

To:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov>:  Patrick  Kelly  (Sheriff) 
<Patrick.Kellv@cookcountyil.gov>;  Christopher  Moore  (Sheriff)  <Christopher.Moore@cookcountyil.gov> 

Subject:  FW:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers  Affected  by#BlueLeaks  Data 
Breach -TLP:  AMBER 
Importance:  High 


FYI, 

You  may  want  to  check  out  this  alert  and  URL. 

Data  breach  affected:  Illinois  Crime  Reporting  and  Information  -  Metro  East 
https://www.bleepingcomputer.com/news/securitv/blueleaks-data-dump-exposes-over-24-years-of-police-records/ 


Jonathan  Springborn 
Jonathan.Springborn@cookcountyil.gov 

(773)674-6850 -Helpdesk 
(773)674-7762  -  Office  Desk  Phone 


From:  MS-ISAC  Advisory  <MS-ISAC.Advisory(5)msisac.org> 

Sent:  Tuesday,  June  23,  2020  11:04  AM 

To:  Michael  Aliperti  <Michael.Aliperti(5)cisecuritv.org>;  Ben  Spear  <Ben.Spear(a>cisecuritv.org> 

Subject:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data 
Breach -TLP:  AMBER 


External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 


TLP:  AMBER 


TO:  All  MS-ISAC  Members  and  Partners 
DATE:  June  23,  2020 

SUBJECT:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data  Breach 

On  June  19,  2020,  a  Twitter  account  announced  the  leak  of  10  years  of  data  from  police  departments, 
fusion  centers,  and  other  law  enforcement-related  entities  currently  being  tracked  on  social  media  as 
#BlueLeaks.  According  to  the  National  Fusion  Center  Association  (NFCA),  the  leak  is  the  result  of  a 
compromise  at  a  third  party  web  hosting  company,  Netsential. 

The  Twitter  account  is  associated  with  Distributed  Denial  of  Secrets  (DDOS),  a  collective  known  for  posting 
leaked  or  exfiltrated  data.  The  post  included  a  link  to  a  Dark  Web  location  hosting  269GB  of  files  and 
emails  including  bulletins,  advisories,  and  guides. 

Upon  receiving  notification  of  this  data  breach,  the  MS-ISAC  has  confirmed  the  existence  of  the  dataset 
and  is  currently  working  to  analyze  the  specific  contents  of  the  data  along  with  our  federal,  state,  and  local 
partners.  At  this  time,  some  MS-ISAC  products  and  correspondence  have  been  identified  in  the  leaked  data 
due  to  the  nature  of  our  relationship  with  fusion  centers  and  law  enforcement  entities.  It  is  likely  that  cyber 
threat  actors  will  utilize  MS-ISAC  information  and/or  other  portions  of  the  data  dump  to  create  tailored 
phishing  campaigns  or  conduct  other  malicious  cyber  activity. 

Recommendations: 

•  Be  vigilant  for  new  waves  of  phishing  campaigns  spoofing  emails  or  products. 

•  Implement  Sender  Policy  Framework  (SPF),  Domain  Keys  Identified  Mail  (DKIM),  and  Domain- 
Based  Message  Authentication  Reporting  and  Conformance  (DMARC),  which  will  assist  in  ensuring 
that  senders  are  unable  to  spoof  your  email  domain.  For  assistance  in  implementing  these  controls, 
see  the  Global  Cyber  Alliance’s  DMARC  Guide  https://dmarcquide.qlobalcvberalliance.Org/#/. 

•  Ensure  anti-virus  software  is  up  to  date. 

•  Remind  users  not  to  visit  un-trusted  websites  or  follow  links  provided  by  unknown  or  un-trusted 
sources. 

•  Apply  the  Principle  of  Least  Privilege  to  all  systems  and  services. 

The  MS-ISAC  continues  to  monitor  this  situation  closely  and  will  release  further  information  as  appropriate. 
24x7  Security  Operations  Center 

Multi-State  Information  Sharing  and  Analysis  Center  (MS-ISAC) 

Elections  Infrastructure  Information  Sharing  and  Analysis  Center  (EI-ISAC) 

31  Tech  Valley  Drive 
East  Greenbush,  NY  12061 
SOC@cisecuritv.org  -  1-866-787-4722 


®  MS-ISAC  ik  infrastructure 

I  SAC 

oooo 


TLP:  AMBER 

Limited  Disclosure,  restricted  to  participants'  organizations.  Recipients  may  only  share  TLP: 
AMBER  information  with  members  of  their  own  organization,  and  with  clients  or  customers  who 
need  to  know  the  information  to  protect  themselves  or  prevent  further  harm. 

http://www.us-cert.gov/tlp/ 

This  message  and  attachments  may  contain  confidential  information.  If  it  appears  that  this  message  was  sent  to  you 
by  mistake,  any  retention,  dissemination,  distribution  or  copying  of  this  message  and  attachments  is  strictly 
prohibited.  Please  notify  the  sender  immediately  and  permanently  delete  the  message  and  any  attachments. 


RE:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers 
Affected  by  #BlueLeaks  Data  Breach  -  TLP:  AMBER 

From:  Jonathan  Springborn  (Sheriff)  </0=EXCHANGELABS/OU=EXCHANGE 

ADMINISTRATIVE  GROUP 

(FYDIBOHF23SPDLT)/CN=RECIPIENTS/CN=32F2AOA9AA124C638CA1784E3422B46 
4-JONATHAN  SP> 

To:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov>,  Patrick  Kelly  (Sheriff) 

<Patrick.Kelly@cookcountyil.gov>,  Christopher  Moore  (Sheriff) 
<Christopher.Moore@cookcountyil.gov> 

Sent:  June  24,  2020  2:02:23  PM  CDT 

Received:  June  24,  2020  2:02:00  PM  CDT 

Awesome! 

Glad  our  data  was  not  leaked. 

Springborn 

Jonathan  Springborn 
Jonathan.Springborn@cookcountyil.gov 

(773)674-6850 -Helpdesk 
(773)674-7762  -  Office  Desk  Phone 


From:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

Sent:  Wednesday,  June  24,  2020  12:33  PM 

To:  Jonathan  Springborn  (Sheriff)  <Jonathan.Springborn@cookcountyil.gov>;  Patrick  Kelly  (Sheriff) 
<Patrick.Kelly@cookcountyil.gov>;  Christopher  Moore  (Sheriff)  <Christopher.Moore@cookcountyil.gov> 

Subject:  RE:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data 
Breach -TLP:  AMBER 


See  attached  from  the  data  breach 


From:  Jonathan  Springborn  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  4:28  PM 

To:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov>:  Patrick  Kelly  (Sheriff) 
<Patrick.Kellv@cookcountyil.gov>:  Christopher  Moore  (Sheriff)  <Christopher.Moore@cookcountyil.gov> 

Subject:  FW:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data 
Breach -TLP:  AMBER 
Importance:  High 

FYI, 

You  may  want  to  check  out  this  alert  and  URL. 


Data  breach  affected:  Illinois  Crime  Reporting  and  Information  -  Metro  East 


https://www.bleepingcomputer.com/news/securitv/blueleaks-data-dump-exposes-over-24-years-of-police-records/ 


Jonathan  Springborn 
Jonathan.Springborn@cookcountyil.gov 

(773)674-6850 -Helpdesk 
(773)674-7762  -  Office  Desk  Phone 


From:  MS-ISAC  Advisory  <MS-ISAC.Advisory@msisac.org> 

Sent:  Tuesday,  June  23,  2020  11:04  AM 

To:  Michael  Aliperti  <Michael.Aliperti@cisecuritv.org>;  Ben  Spear  <Ben. Spear@cisecurity.org> 

Subject:  Message  from  the  MS/EI-ISAC:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data 
Breach -TLP:  AMBER 


External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 


TLP:  AMBER 


TO:  All  MS-ISAC  Members  and  Partners 
DATE:  June  23,  2020 

SUBJECT:  200+  Police  Departments,  Fusion  Centers  Affected  by  #BlueLeaks  Data  Breach 

On  June  1 9,  2020,  a  Twitter  account  announced  the  leak  of  1 0  years  of  data  from  police  departments, 
fusion  centers,  and  other  law  enforcement-related  entities  currently  being  tracked  on  social  media  as 
#BlueLeaks.  According  to  the  National  Fusion  Center  Association  (NFCA),  the  leak  is  the  result  of  a 
compromise  at  a  third  party  web  hosting  company,  Netsential. 

The  Twitter  account  is  associated  with  Distributed  Denial  of  Secrets  (DDOS),  a  collective  known  for  posting 
leaked  or  exfiltrated  data.  The  post  included  a  link  to  a  Dark  Web  location  hosting  269GB  of  files  and 
emails  including  bulletins,  advisories,  and  guides. 

Upon  receiving  notification  of  this  data  breach,  the  MS-ISAC  has  confirmed  the  existence  of  the  dataset 
and  is  currently  working  to  analyze  the  specific  contents  of  the  data  along  with  our  federal,  state,  and  local 
partners.  At  this  time,  some  MS-ISAC  products  and  correspondence  have  been  identified  in  the  leaked  data 
due  to  the  nature  of  our  relationship  with  fusion  centers  and  law  enforcement  entities.  It  is  likely  that  cyber 
threat  actors  will  utilize  MS-ISAC  information  and/or  other  portions  of  the  data  dump  to  create  tailored 
phishing  campaigns  or  conduct  other  malicious  cyber  activity. 

Recommendations: 

•  Be  vigilant  for  new  waves  of  phishing  campaigns  spoofing  emails  or  products. 

•  Implement  Sender  Policy  Framework  (SPF),  Domain  Keys  Identified  Mail  (DKIM),  and  Domain- 
Based  Message  Authentication  Reporting  and  Conformance  (DMARC),  which  will  assist  in  ensuring 
that  senders  are  unable  to  spoof  your  email  domain.  For  assistance  in  implementing  these  controls, 
see  the  Global  Cyber  Alliance’s  DMARC  Guide  https://dmarcquide.qlobalcvberalliance.Org/#/. 

•  Ensure  anti-virus  software  is  up  to  date. 

•  Remind  users  not  to  visit  un-trusted  websites  or  follow  links  provided  by  unknown  or  un-trusted 
sources. 

•  Apply  the  Principle  of  Least  Privilege  to  all  systems  and  services. 

The  MS-ISAC  continues  to  monitor  this  situation  closely  and  will  release  further  information  as  appropriate. 
24x7  Security  Operations  Center 

Multi-State  Information  Sharing  and  Analysis  Center  (MS-ISAC) 

Elections  Infrastructure  Information  Sharing  and  Analysis  Center  (EI-ISAC) 

31  Tech  Valley  Drive 
East  Greenbush,  NY  12061 
SOC@cisecuritv.org  -  1-866-787-4722 


©  MS-ISAC’  -k  Infrastructure 

I  SAC 

OOOO 


TLP:  AMBER 

Limited  Disclosure,  restricted  to  participants'  organizations.  Recipients  may  only  share  TLP: 
AMBER  information  with  members  of  their  own  organization,  and  with  clients  or  customers  who 
need  to  know  the  information  to  protect  themselves  or  prevent  further  harm. 

http://www.us-cert.gov/tlp/ 

This  message  and  attachments  may  contain  confidential  information.  If  it  appears  that  this  message  was  sent  to  you 
by  mistake,  any  retention,  dissemination,  distribution  or  copying  of  this  message  and  attachments  is  strictly 
prohibited.  Please  notify  the  sender  immediately  and  permanently  delete  the  message  and  any  attachments. 


RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


To:  Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov> 

Cc:  Adrian  Memon  (Sheriff)  <Adnan.Memon@cookcountyil.gov>,  Douglas 

Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov>,  Michael.Tomasiello 
(Chicago  Police)  <Michael.Tomasiello@chicagopolice.org> 

Received:  June  24,  2020  2:24:57  PM  CDT 

Attachments:  imageOOl  .png,  domains  they  own.txt 

From  the  best  I  can  tell  digging  into  their  supply  chain  they  are  a  Microsoft  shop  not  AWS. 


Supply  Chain  © 


Netsential.Com  (netsential.com)  Business  Data 

Customer  Data  3  W 

Category  /  Vendor  ^ 

Main  Website 

Widgets  (1)  v 


Webserver  (2)  ^ 

Microsoft 

microsoft.com 

Microsoft  IIS 

iis.net 

Webmaster  tools  (1)  ^ 

Google 


google.com 


Their  website  relates  they  are  working  with  LE  at  the  moment. 

The  owner  was 

I  contacted  Tomasiello  at  CPD  waiting  for  a  response  from  him. 

From:  Amar  Patel  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  8:53  PM 

To:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

Cc:  Adnan  Memon  (Sheriff)  <Adnan.Memon@cookcountyil.gov>;  Douglas  Maclean  (Sheriff) 
<Douglas.Maclean2@cookcountyil.gov> 

Subject:  Re:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 
Hi  Keith, 

Is  our  Azure  data  center  affiliated  with  Netsential?  I  would  think  not,  but  can  we  verify.  Can  you  also  see  if 
CPD  (CPIC)  was  included  in  the  leak?  Intel  works  with  them  with  reports  and  officer  safety  bulletins.  I 
think  they  host  internally  or  on  AWS,  but  not  sure.  Thanks  sir. 


Thanks, 
Amar  Patel 


From:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

Sent:  Tuesday,  June  23,  2020  7:10  AM 

Cc:  Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov>:  Adnan  Memon  (Sheriff) 
<Adnan.Memon@cookcountyil.gov>:  Douglas  Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov> 

Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

This  is  a  different  article  from  the  International  Association  of  Chiefs  of  Police  that  relates  Netsentinal  is  a  Houston 
service  provider  for  Law  Enforcement. 

https://www.theblaze.com/news/blueleaks-hackers-release-countless-records-on-police-officers-all-searchable-by- 

badge-number 

I  think  our  only  risk  from  doxing  would  be  workforce.  I  pulled  the  attached  reports  last  Friday  and  provided  them  to 
Chuck  at  Homeland  for  review. 

From:  Keith  Morrison  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:45  AM 

To:  Douglas  Maclean  (Sheriff)  <Douglas. Maclean2@cookcountvil.gov> 

Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


From:  Douglas  Maclean  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:26  AM 

To:  Keith  Morrison  (Sheriff)  <Keith. Morrison@cookcountvil.gov>:  Amar  Patel  (Sheriff) 

<Amar. Patel@cookcountvil.gov>:  Adnan  Memon  (Sheriff)  <Adnan. Memon@cookcountvil.gov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


Keith  - 


Doug 

From:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

Sent:  Tuesday,  June  23,  2020  6:20  AM 

To:  Douglas  Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov>:  Amar  Patel  (Sheriff) 
<Amar.Patel@cookcountyil.gov>:  Adnan  Memon  (Sheriff)  <Adnan.Memon@cookcountyil.gov> 
Subject:  RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Deputy  CIO  Maclean, 


Thanks, 

Morrison 


From:  Douglas  Maclean  (Sheriff) 

Sent:  Tuesday,  June  23,  2020  6:10  AM 

To:  Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov>:  Keith  Morrison  (Sheriff) 
<Keith.Morrison@cookcountyil.gov>:  Adnan  Memon  (Sheriff)  <Adnan.Memon@cookcountyil.gov> 

Subject:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 

Krebs  on  Security  reports  Blue  Leaks  has  posted  24  years  of  LEA  and  fusion  center-related  data  as  the  result  of  a 
breach  on  Netsential,  an  internet  services  provider  to  LEAs  and  operational  fusion  centers.  The  data  includes  some 
information  related  to  sensitive  operations  and  a  significant  amount  of  Pll. 

The  Krebs  on  Security  story  can  be  found  here 

Keith  -  do  we  have  any  exposure  from  this  breach  either  directly  from  our  own  infrastructure  or  indirectly  as  the 
result  of  data-sharing  with  other  agencies?  Do  any  of  our  vendors  use  or  have  they  used  Netsential  for  any  of  their 
operations  from  1994  to  present? 


Douglas  MacLean 
Deputy  CIO 

Cook  County  Sheriffs  Office 
3026  S.  California 
South  Campus  Building  1 
Chicago  IL  60608 
312.877.2048  [c] 
773.674.8615  [d] 


RE:  IMPORTANT:  Blue  Leaks  Posts  24  Years  of  Fusion  Center  Data 


From:  Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 

To:  Amar  Patel  (Sheriff)  <Amar.Patel@cookcountyil.gov> 

Cc:  Adnan  Memon  (Sheriff)  <Adnan.Memon@cookcountyil.gov>,  Douglas 

Maclean  (Sheriff)  <Douglas.Maclean2@cookcountyil.gov> 

Sent:  June  24,  2020  2:28:43  PM  CDT 

Received:  June  24,  2020  2:28:43  PM  CDT 

Attachments:  domains  they  own.txt 

From  the  best  I  can  tell  digging  into  their  supply  chain  they  are  a  Microsoft  shop  not  AWS. 


Threat  Actor  Sold  Access  to  Networks  of  135  Organizations: 


From: 

To: 

Sender: 

Sent: 

Received: 


SecurityWeek  Briefing  <news@securityweek.com> 
jonathan.springborn@cookcountyil.gov,  Jonathan  Springborn  (Sheriff) 
<Jonathan.  Springborn@cookcountyil.gov> 

SecurityWeek  Briefing  <news@securityweek.ccsend.com> 

June  24,  2020  3:23:27  PM  CDT 
June  24,  2020  3:23:31  PM  CDT 


External  Message  Disclaimer 

j  This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 


Visit  SecuritvWeek.Com  |  Advertise  |  Contact 


RSS  Feed 


06.24.20 


Sodinokibi  Ransomware  Operators  Target  POS 
Software:  The  threat  actor  behind  the  Sodinokibi 
ransomware  was  observed  scanning  the  victim 
networks  for  credit  card  or  point  of  sale  (POS)  software. 

Read  More 

Threat  Actor  Sold  Access  to  Networks  of  135 
Organizations:  Over  a  period  of  two  years,  a  threat 
actor  sold  access  to  the  compromised  networks  of  135 
organizations  in  44  countries  and  likely  made  over  $1.5 
million.  Read  More 

VMware  Patches  Several  Vulnerabilities  Allowing 
Code  Execution  on  Hypervisor:  VMware  addresses 


Why  Does  Asset  Management 

Matter  for  Cvbersecuritv? 

Download  the  free  white  paper  today  to  learn  why 
modern  asset  management  is  the  nexus  for 
cybersecurity  projects  and  decisions. 

Read  Now 


Defending  Your  Budget:  How  to  Show  ROI  of 
Cybersecurity  Investments 

developing  an  ROI  model  takes  time  n  my  recommendation  would  be  to 
focus  on  a  simple  security  project  that  will  return  high  value  to  the 
business  when  proven  successful. 

Read  the  Full  Column  by  Laurence  Pitt 


Non-Human  Identities:  The  New  Blindspot  in 
Cybersecurity 

i  rie  integration  of  identity  with  security  is  still  work  in  progress,  with  less 
than  half  of  businesses  having  fully  implemented  key  identity-related 
access  controls  according  to  a  research  study. 

Read  the  Full  Column  by  Torsten  George 


New  Reality  of  IT-OT:  Convergence,  Collaboration  and 
Digital  Transformation  Acceleration 

ilis  very  challenging  for  OT  professionals  to  play  catch  up  and  close  the 
25+  year  IT-OT  security  gap,  particularly  as  the  number  of  connectivity 
points  grows  exponentially. 

Read  the  Full  Column  by  Galina  Antova 


To  Err  Is  Human:  Accepting  Responsibility  to  Regain 
Confidence 

regardless  of  what  goes  wrong,  the  right  attitude  goes  a  long  way 
towards  helping  stakeholders  regain  confidence  in  the  security  team  and 
the  security  program  it  is  running. 

Read  the  Full  Column  by  Joshua  Goldfarb 


Navigating  the  Rapid  Digital  Shift:  Ticket  on  the  Bus, 
Not  the  Whole  Bus 

vvicn  a  diverse  and  globally  distributed  workforce,  cybersecurity  buying 
decisions  will  increasingly  factor  accessibility,  usability,  and  inclusiveness 
in  solution  design  and  operability. 

Read  the  Full  Column  by  Gunter  Ollmann 


SD-WAN  Must  Be  Secure,  Flexible,  and  Scale  Across 
the  Entire  Enterprise 

amart  businesses  are  learning  that  SD-WAN  can  play  a  critical  role  in 
quicklyoand  securelyorolling  out  new  networking  environments,  and 


10  vulnerabilities  in  ESXi,  Workstation  and  Fusion 
products,  including  serious  flaws  that  can  be  exploited 
for  code  execution  on  the  hypervisor.  Read  More 

Dridex  Operators  Develop  'WastedLocker' 
Ransomware:  The  threat  actor  behind  the  Dridex 
Trojan  has  released  a  new  ransomware  following 
months  of  development.  Read  More 

Bug  Hunters  Confident  They  Will  Continue  to 
Outperform  AI:  Study:  Hackers  are  confident  that 
they  will  outperform  AI  for  the  next  10  years  when  it 
comes  to  finding  vulnerabilities,  Bugcrowd  study  shows. 

Read  More 

Senators  Introduce  "Balanced"  Bill  That  Aims  to 
End  Warrant-Proof  Encryption:  Republican  senators 
have  introduced  what  they  have  described  as  a 
ibalancedi  bill  that  would  require  tech  companies  to  give 
law  enforcement  access  to  encrypted  data. Read  More 

Companies  Say  Strong  Authentication  Important 
But  Still  Over-Rely  on  Passwords:  Companies 
believe  strong  authentication  is  important,  but  they  still 
over-rely  on  passwords  and  allow  their  employees  to 
access  corporate  resources  via  social  media  credentials. 
Read  More 

Twitter  Suspends  Account  of  Organization  Behind 
Police  Leaks:  Twitter  has  suspended  the  account  of 
Distributed  Denial  of  Secrets  after  it  posted  links  to 
information  on  200  law  enforcement  organizations. 

Read  More 

German  Court  Orders  Facebook  to  Rein  in  Data 
Collection:  A  top  German  court  has  ordered  Facebook 
to  stop  merging  data  collected  through  its  Whatsapp 
and  Instagram  subsidiaries  or  other  websites  unless 
users  explicitly  agree,  in  a  legal  victory  for  competition 
authorities.  Read  More 

Microsoft  Chief  Says  EU  'Most  Influential'  on  Tech 
Rules:  Microsoft  president  Brad  Smith  on  Tuesday  said 
Europe  was  the  global  leader  on  setting  rules  for  big 
tech,  two  years  after  the  EU  implemented  the  GDPR,  its 
landmark  data  privacy  law.  Read  More 

Safe  Documents  Feature  in  Microsoft  365  Apps 
Now  Generally  Available:  Microsoft  this  week 
announced  that  Safe  Documents,  a  feature  meant  to 
boost  the  protection  of  Microsoft  365  users  when 
opening  unsafe  documents,  is  generally  available.  Read 
More 

COVID-19  Fuels  Phishing  and  Scams  While  BEC 
Attacks  Evolve  and  Increase:  COVID-19  is  fueling 
phishing  and  scams  while  BEC  attacks  continue  to 
evolve  and  increase,  according  to  a  report  from 
Abnormal  Security.  Read  More 

Twitter  Alerts  Business  Users  of  Billing 
Information  Exposure:  Twitter  has  informed  business 
users  that  their  billing  information  may  have  been 
exposed  through  their  web  browsens  cache.  Read 
More 

Micro-Segmentation  for  Endpoints  Shows 
Promising  Defense  Against  Lateral  Movement: 

Applying  micro-segmentation  to  endpoints  can  help 


connecting  resources  and  users  to  data  and  applications. 

Read  the  Full  Column  by  John  Maddison 


Strengthen  Cybersecurity  With  These  3  Steps  to  Rapid 
Response 

vviui  capabilities  to  quickly  curate  and  integrate  new  threat  data  sources 
across  your  operations,  youire  prepared  for  whatever  the  future  brings. 

Read  the  Full  Column  by  Marc  Solomon 


3  Ways  Effective  OT  Security  Enables  Your 
Business 

When  your  core  business  operations,  digital  transformation  initiatives  and 
workers!  ability  to  do  their  jobs  are  at  risk,  effective  OT  security  must 
become  just  as  ubiquitous. 

Read  the  Full  Column  by  Galina  Antova 


Realizing  the  Potential  of  AI-Driven  Security 
Operations 

oy  combining  ML  and  AI  with  a  team  of  advanced  cybersecurity 
professionals  to  deploy  true  Al-driven  security  operations,  organizations 
can  stay  a  step  ahead  of  cybercriminals. 

Read  the  Full  Column  by  John  Maddison 


Protecting  Online  Retail  in  the  Face  of  COVID-19  and 
Beyond 

every  business  is  likely  to  be  subject  to  cyberattacks  at  some  point,  and 
the  option  is  to  either  take  on  the  cost  of  putting  measures  in  place  before 
it  happens  or  paying  to  clean  up  after. 

Read  the  Full  Column  by  Laurence  Pitt 


On  the  Rise:  The  Enemy  From  Within 

luuay's  economic  climate  exacerbates  risks  of  insider  threats,  as  pending 
furloughs  or  pay  cuts  may  tempt  employees  to  exfiltrate  data  to  secure  a 
new  job,  make  up  for  income  losses,  etc. 

Read  the  Full  Column  by  Torsten  George 


Seven  Ways  to  Improve  Efficiency  in  Your  Security 
Metrics  Program 

nost  security  organizations  realize  that,  regardless  of  how  much  progress 
they've  made  towards  improving  maturity  and  efficiency,  there  is  still 
more  work  to  be  done. 

Read  the  Full  Column  by  Joshua  Goldfarb 


Why  You  May  Not  Need  to  Monitor  the  Dark  Web 

many  organizations  are  steadfast  in  their  belief  that  dark  web  monitoring 
is  a  critical  part  of  their  security  operations  and  the  security  industry  is 
happy  to  fuel  that  belief. 

Read  the  Full  Column  by  Idan  Aharoni 


stop  attackers  from  moving  laterally  within  an 
organization  after  the  initial  breach.  Read  More 

XORDDoS,  Kaiji  DDoS  Botnets  Target  Docker 
Servers:  The  XORDDoS  and  Kaiji  DDoS  botnets  have 
started  targeting  exposed  Docker  servers,  Trend  Micro 
warns.  Read  More 

U.S.  Pushes  for  HTTPS  on  .gov  Domains:  The 

United  States  is  taking  additional  steps  toward  serving 
.gov  domains  over  encrypted  connections,  and  this 
week  laid  out  plans  to  preload  the  entire  top-level 
domain  (TLD).  Read  More 

Apple  Announces  New  Privacy  Features  at  WWDC 
2020:  Apple  has  announced  several  new  privacy  and 
security  features  at  its  2020  Worldwide  Developers 
Conference  (WWDC).  Read  More 

Mitsubishi  Patches  Vulnerabilities  Disclosed  at 
ICS  Hacking  Contest:  Mitsubishi  Electric  and  its 
subsidiary  ICONICS  have  released  patches  for  the 
vulnerabilities  disclosed  earlier  this  year  at  the 
Pwn20wn  hacking  competition  targeting  ICS.  Read 
More 

N. Zealand  Freezes  Assets  of  Alleged  Russian 
Cyber  Criminal:  New  Zealand  police  has  frozen 
NZ$140  million  (US$90  million)  in  assets  linked  to  a 
Russian  man  accused  of  laundering  money  for 
organised  crime  using  cyber  currency.  Read  More 

Microsoft  Acquires  Industrial  Cybersecurity 
Company  CyberX:  Microsoft  has  acquired  industrial 
cybersecurity  company  CyberX  in  an  effort  to  expand 
its  Azure  IoT  security  capabilities  and  extend  them  to 
IIoT  and  OT.  Read  More 

Vulnerability  in  OSIsoft  PI  System  Can  Facilitate 
Attacks  on  Critical  Infrastructure:  A  stored  XSS 
vulnerability  in  OSIsoft  PI  System,  a  product  often 
present  in  critical  infrastructure  facilities,  can  be 
exploited  for  phishing,  privilege  escalation  and  other 
purposes.  Read  More 

Spyware  by  Israel's  NSO  Used  Against  Journalist: 
Amnesty:  Amnesty  International  says  software 
developed  by  Israeli  security  firm  NSO  Group  was  used 
to  attack  a  Moroccan  journalist,  the  latest  in  a  series  of 
allegations  against  the  company.  Read  More 

BlueLeaks:  Data  From  Hundreds  of  Law 
Enforcement  Organizations  Leaked  Online: 

BlueLeaks:  Distributed  Denial  of  Secrets  has  leaked 
hundreds  of  thousands  of  files  belonging  to  over  200 
law  enforcement  agencies,  obtained  by  Anonymous 
hackers  from  a  web  development  firm.  Read  More 

Microsoft  Boosts  Protections  for  US  AccountGuard 
Users:  Microsoft  has  announced  improved  identity  and 
access  management  protections  for  AccountGuard  users 
in  the  United  States,  ahead  of  the  2020  elections.  Read 
More 

AMD  Preparing  Patches  for  UEFI  SMM 
Vulnerability:  AMD  is  preparing  patches  for  a 
vulnerability  affecting  the  System  Management  Mode 
(SMM)  of  the  UEFI  shipped  for  some  notebook  and 
embedded  processors.  Read  More 


Data  is  the  Key  to  Understand  Whatever  Life 
Brings 

With  an  extensible  platform  and  flexible  data  model,  you  can  take  full 
advantage  of  the  volume  and  variety  of  data  to  gain  insights,  and  the 
technologies  in  your  ecosystem  to  accelerate  detection  and  response  and 
mitigate  risk. 

Read  the  Full  Column  by  Marc  Solomon 


Beware  of  Sick  Behavior  Masquerading  as 
Coronavirus 

Researchers  have  undertaken  a  deep  dive  into  the  shadowy,  cyber  world 
of  those  whose  work  involves  abusing  others  online  through  trickery, 
extortion,  fraud,  and  theft  resulting  from  COVID-19. 

Read  the  Full  Column  by  Alastair  Paterson 


Three  Tips  to  Help  CISOs  Close  the  IT-OT  Security 
Gap,  Part  2 

eliminate  complexity,  align  IT  and  OT  teams,  and  simplify  governance  are 
my  top  three  recommendations  for  how  to  bridge  the  IT-OT  security  gap. 

Read  the  Full  Column  by  Galina  Antova 


Now  That  Everyone's  Working  From  Home,  How's 
Your  Helpdesk  Holding  Up? 

neiyhtened  anxiety  is  a  normal  consequence  of  drastic  change,  and  it's 
natural  for  the  entire  organization  to  be  stressed  by  the  shift  to  a  fully 
remote  work  environment. 

Read  the  Full  Column  by  Jim  Ducharme 
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U.S.  Sanctions  Six  Nigerians  for  BEC  and  Romance 
Fraud:  The  U.S.  Treasury  Department  and  the  Justice 
Department  announce  sanctions  against  six  Nigerian 
nationals  for  their  involvement  in  BEC  and  romance 
fraud  schemes.  Read  More 

Google  Loses  Appeal  Against  50-Mn-Euro  French 
Fine:  France's  highest  administrative  authority  on 
Friday  dismissed  a  challenge  by  Google  against  a  fine  of 
50  million  euros  ($56  million)  for  failing  to  provide 
adequate  information  on  its  data  consent  policies.  Read 


Tens  of  Malicious  Chrome  Extensions  Used  in 
Global  Surveillance  Campaign:  Malicious  Chrome 
extensions  employed  in  a  massive  global  surveillance 
campaign  have  been  downloaded  by  millions  before 
removal.  Read  More 

Flaw  in  IBM  Asset  Management  Product 
Facilitates  Attacks  on  Corporate  Networks:  A  high- 
severity  vulnerability  found  in  IBMfs  Maximo  asset 
management  product  makes  it  easier  for  hackers  to 
move  around  in  enterprise  networks.  Read  More 

Man  Accused  of  Hacking  University  of  Pittsburgh 
Medical  Center  Gets  Arrested:  The  alleged  hacker 
who  breached  the  human  resource  databases  of 
University  of  Pittsburgh  Medical  Center  in  2014  was 
arrested  this  week  in  Detroit.  Read  More 

Mysterious  'AcidBox'  Malware  Used  Turla  Exploit 
to  Target  Russian  Organizations:  Targeted  attacks 
delivering  a  new  piece  of  malware  leveraged  an  exploit 
previously  associated  with  the  Russian-linked  Turla 
hacking  group.  Read  More 
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This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 


Ransomware  perspectives:  The  shape  of  things  to  come  -  Interview  with  CISO 
Mike  Hamilton 

Mike  Hamilton,  CISO  of  Cl  Security,  discusses  ransomware  attacks  and  offers 
insight  on  how  to  strengthen  the  cybersecurity  program  to  defend  against  new  TTPs 
by  threat  actors.  Mike  discusses  the  impacts  ransomware  attacks  have  on  cities  and 
how  properly  staffing  up  on  InfoSec  talent  is  critical  to  managing  ransomware  risks. 
“Your  monitoring  must  be  comprehensive,  and  someone  must  be  assigned  to  follow 
up  and  investigate  security  alerts,”  notes  Mike.  “Without  proper  people  resourcing, 
your  technology  is  yelling  into  the  wind.  Ask  Target  how  this  works  out.” 

https://www.helpnetsecuritv.com/2020/06/24/ransomware-perspectives/ 


New  WastedLocker  ransomware  demands  payments  of  millions  of  USD 

In  an  interview  with  ZDNet  earlier  today,  Fox-IT  says  they've  been  tracking  the  use  of 
this  new  ransomware  family  since  May  2020.  They  say  the  ransomware  has  been 
exclusively  deployed  against  US  companies.  "Ransom  demands  that  are  asked  by 


Evil  Corp  are  now  typically  into  the  millions,"  Maarten  van  Dantzig,  Fox-IT  security 
researcher,  told  ZDNet  today.  "We've  seen  demands  of  more  than  $10  million,"  he 
added.  [...]  "Typically,  they  hit  file  servers,  database  services,  virtual  machines,  and 
cloud  environments,"  researchers  said. 

https://www.zdnet.com/article/new-wastedlocker-ransomware-demands-pavments- 

of-millions-of-usd/ 


Fxmsp  hackers  made  $1.5M  selling  access  to  corporate  networks 

Fxmsp  became  widely  known  outside  hacker  forums  about  a  year  ago  when 
cybersecurity  boutique  Advanced  Intelligence  (Advlntel)  published  a  series  of  reports 
on  the  actor’s  attempts  to  close  a  $300,000  deal  for  selling  access  to  networks 
belonging  to  Symantec,  Trend  Micro,  and  McAfee.  [...]  According  to  Yelisey 
Boguslavskiy,  Advlntel  director  of  security  research,  Fxmsp  was  the  hacking  part  of  a 
crew  (GPTitan)  consisting  of  specialists  "geared  to  secretly  work  in  financial 
environments"  to  steal  from  high-profile  networks  data  relevant  to  customers. 

https://www.bleepingcomputer.com/news/security/fxmsp-hackers-made-15m-selling- 

access-to-corporate-networks/ 


Bungled  Lancet  study  casts  shadow  over  health  data  industry 

The  ensuing  scandal  threw  a  damper  on  the  idea  of  medical  research  being  based 
entirely  on  big  sets  of  health  data,  at  a  time  when  the  market  for  health  data  is 
booming  and  big  industrial  players  are  pushing  for  its  use  in  medical  research. 
Google  this  week  formally  notified  the  European  Commission  of  its  plans  to  buy 
wearable  health  tracking  devices  company  Fitbit  —  and  its  troves  of  sensitive  health 
data  —  in  a  deal  that  has  alarmed  privacy  campaigners,  while  Palantir,  a  U.S.  data 
mining  company,  recently  gained  access  to  U.K.  health  data. 

https://www.politico.com/news/2020/06/24/lancet-studv-hvdroxychloroguine-health- 

data-industry-337663 


3  Key  Ways  to  Bolster  Healthcare  Cybersecurity  with  MFA,  Training 

For  the  healthcare  sector,  already  burdened  with  the  Coronavirus  response,  the 


expanded  threat  landscape  could  lead  to  some  serious  issues  down  the  line. 
Fortunately,  the  majority  of  these  advisories  contain  key  elements  that  could  allow 
enterprises  to  effectively  close  some  of  these  critical  gaps. 

MULTI-FACTOR  AUTHENTICATION 

USER  EDUCATION,  TRAINING 

ASSET  INVENTORY  AND  PATCH  MANAGEMENT 

https://healthitsecuritv.com/news/3-kev-wavs-to-bolster-healthcare-cvbersecuritv- 

with-mfa-training 


CISA’s  Ware  Runs  Down  COVID-19  Cyber  Threats  to  Health  Sectors 

Despite  the  massive  turn  to  telework  at  government  agencies  and  in  the  private 
sector  during  the  pandemic  -  and  the  accompanying  assault  of  cyber  attacks  from 
actors  looking  to  take  advantage  of  the  situation  -  Ware  said  that  CISA  has 
continued  on  pace  with  other  missions,  including  effort  to  secure  the  national 
elections  in  November.  He  said  the  “risk  picture”  for  CISA  has  shown  up  strongly  in 
four  categories:  phishing  exploit  increases;  ransomware  attacks  on  healthcare 
systems;  espionage  against  pharmaceutical  companies  and  laboratories;  and  risks 
involved  with  shift  to  telework. 

https://www.meritalk.com/articles/cisas-ware-runs-down-covid-19-cvber-threats-to- 

health-sectors/ 


Indiabulls  Group  hit  by  CLOP  Ransomware,  gets  24h  leak  deadline 

"The  Indiabulls  Group  is  a  diversified  financial  services  group  with  interests  in 
housing  finance,  consumer  finance  and  personal  wealth.  The  Group  also  has  a 
presence  in  Real  Estate,  Pharmaceuticals,  Lighting  and  Infrastructure  &  Construction 
Equipment  Leasing[.]"  [...]  Cyberintelligence  firm  Bad  Packets  told 
BleepingComputer,  though,  that  Indiabulls  has  an  Citrix  Netscaler  ADC  VPN 
gateway  exposed,  which  is  vulnerable  to  the  CVE-201 9-1 9781  vulnerability. 

https://www.bleepingcomputer.com/news/security/indiabulls-group-hit-bv-clop- 

ransomware-gets-24h-leak-deadline/ 


FBI,  DoJ  Officials  Warn  of  Common  COVID-19  Cyber  Threat  Vectors 

Tonya  Ugoretz,  deputy  assistant  director  of  the  FBI’s  Cyber  Division,  reported  that 
the  agency’s  Internet  Crime  Complaint  Center  has  seen  as  many  complaints  as  this 
point  in  2020  as  they  did  in  all  of  2019.  Of  those  complaints,  she  said  at  the  June  24 
Fal.Con  for  the  Public  Sector  CrowdStrike  Cybersecurity  Conference,  at  least  20,000 
have  been  about  COVID-19  related  schemes. 

https://www.meritalk.com/articles/fbi-doi-officials-warn-of-common-covid-19-cvber- 

threat-vectors/ 


Banks  can  ill  afford  to  get  complacent  about  coronavirus 

[Cyber]  resiliency  in  a  business  continuity  model  is  going  to  be  crucial  to  ensuring  a 
safe  and  secure  financial  system.  Cyber  resiliency  is  broader  than  the  traditional 
business  continuity  focus  on  data  backup  and  recovery.  It’s  about  data  integrity  and 
the  ability  to  trust  the  data  to  know  with  confidence  that  backed-up  data  has  not  been 
corrupted  or  altered  by  a  cyberattack.  Resilience  is  the  ability  to  operate,  even  in  a 
degraded  state,  and  recover  from  deliberate  attacks. 

https://www.americanbanker.com/opinion/banks-can-ill-afford-to-get-complacent- 

about-coronavirus 


There’s  No  Vaccine  For  Data  Leaks:  Why  One  Cyber  Attack  Leads  To  Another 

Businesses  have  become  far  too  accustomed  to  massive  security  breaches, 
disregarding  them  like  the  common  cold.  Often,  the  remedy  appears  to  be  free  credit 
monitoring  for  the  affected.  But  the  real  threat  is  lost  in  that  perception  of  safety  and 
a  healthy  bounce-back.  Many  significant  risks  are  escalated  after  a  breach 
leveraging  the  data  that  is  lost  in  these  incidents  —  stolen  personal  details  enable 
ransomware  or  “man-in-the-middle”  breaches  to  be  more  targeted  and  effective. 

https://www.forbes.com/sites/emilsavegh/2020/06/24/theres-no-vaccine-for-data- 

Ieaks-why-one-cvber-attack-leads-to-another/#58d58a757300 


Senate  wants  more  clarity  on  cyber  ops 

In  its  version  of  the  annual  defense  policy  bill  — which  passed  the  committee  last 
week,  though  full  text  of  the  language  was  only  made  public  this  week  —  the 
committee  takes  aim  at  U.S.  Cyber  Command’s  so-called  hunt  forward  operations. 
Hunt  forward  operations  involve  teams  from  Cyber  Command  physically  deploying  to 
other  nations  to  assist  them  with  cyber  defense.  These  operations  provide  American 
cyber  teams  insight  into  tactics  that  could  be  turned  against  U.S.  networks  or  used  to 
disrupt  the  elections  process,  officials  have  maintained. 

https://www.fifthdomain.com/congress/2020/Q6/24/senate-wants-more-claritv-on- 

cyber-ops  / 


Cyber  attack  on  Israeli  water-treatment  plant  is  one  indication  of  a  rising  tide  of 
cyber  security  issues 

The  water  facility  attack  was  to  release  large  amounts  of  poisonous  chlorine  into 
Israel’s  water  delivery  infrastructure,  potentially  poisoning  tens  of  thousands  of 
Israelis.  It  may  indicate  a  growing  threat  of  cyber  attack  throughout  the  world. 

FireEye,  a  publicly  traded  cyber  security  company  in  Milpitas,  California,  determined 
that  the  malware  developed  for  this  kind  of  attack  came  out  of  Russia  and 
specifically  from  the  Central  Scientific  Research  Institute  of  Chemistry  and 
Mechanics,  a  Russian  government-owned  technical  research  institution  in  Moscow. 

https://www.militarvaerospace.com/trusted-computinq/article/14178333/cvber- 

security-growing-threat-international-actors 


China  is  Retooling,  and  Russia  Seeks  Harm  to  Critical  Infrastructure 

China  and  Russia  continue  to  pose  the  greatest  espionage  and  cyber  attack  threats 
to  the  United  States,  but  the  intelligence  leader  anticipates  that  other  adversaries 
and  strategic  competitors  will  also  build  and  integrate  cyber  espionage,  cyber  attacks 
and  influence  operations  into  how  they  conduct  business.  “Our  strategic  competitors 
will  increasingly  use  cyber  space  capabilities  including  cyber  espionage,  cyber  attack 
and  continued  influence  operations  to  seek  political,  economic  and  military 
advantage  over  the  United  States,  our  allies  and  our  partners,”  he  said.  “This  is  not 
an  ‘if,’  it  is  a  yes.  They  are  doing  it  and  they  will  continue.” 


https://www.afcea.org/content/china-retooling-and-russia-seeks-harm-critical- 

infrastructure 


Police  arrested  wrong  man  based  on  facial  recognition  fail,  ACLU  says 

The  American  Civil  Liberties  Union  filed  the  complaint  (PDF)  Wednesday  on  behalf 
of  Robert  Williams,  a  Michigan  man  who  was  arrested  in  January  based  on  a  false 
positive  generated  by  facial  recognition  software.  "At  every  step,  DPD's  conduct  has 
been  improper,"  the  complaint  alleges.  "It  unthinkingly  relied  on  flawed  and  racist 
facial  recognition  technology  without  taking  reasonable  measures  to  verify  the 
information  being  provided"  as  part  of  a  "shoddy  and  incomplete  investigation." 

https://arstechnica.com/tech-policv/2020/06/police-arrested-wrong-man-based-on- 

facial-recognition-fail-aclu-savs/ 


Twitter  bans  DDoSecrets  account  over  'BlueLeaks'  police  data  dump 

On  Friday,  last  week,  the  group  published  296  GB  of  data  they  claimed  to  have 
received  from  the  Anonymous  hacker  collective.  The  data  dump,  dubbed  BlueLeaks, 
contained  millions  of  documents  that  were  stolen  from  a  Texas  company  named 
Netsential  that  provided  web  hosting  services  for  various  US  law  enforcement 
entities.  Subsequent  analysis  revealed  that  the  BlueLeaks  data  dump  contained  files 
from  more  than  200  US  police  departments,  fusion  centers,  and  other  law 
enforcement  training  and  support  portals. 

https://www.zdnet.com/article/twitter-bans-ddosecrets-account-over-blueleaks-police- 

data-dump/ 


Self-Propagating  Lucifer  Malware  Targets  Windows  Systems 

The  never-before-seen  malware  initially  tries  to  infect  PCs  by  bombarding  them  with 
exploits  in  hopes  of  taking  advantage  of  an  “exhaustive”  list  of  unpatched 
vulnerabilities.  While  patches  for  all  the  critical  and  high-severity  bugs  exist,  the 
various  companies  impacted  by  the  malware  had  not  applied  the  fixes.  [...]  The 
vulnerabilities  targeted  by  Lucifer  include  Rejetto  HTTP  File  Server  (CVE-2014- 
6287),  Oracle  Weblogic  (CVE-201 7-1 0271),  ThinkPHP  RCE  (CVE-20 18-20062), 
Apache  Struts  (CVE-201 7-9791),  Laravel  framework  CVE-201 9-9081),  and 


Microsoft  Windows  (CVE-20 17-0 144,  CVE-201 7-0145,  and  CVE-2 01 7-8464). 

https://threatpost.com/self-propagating-lucifer-malware-targets-windows- 

svstems/1 56883/ 


Republicans  Who  Don’t  Understand  Encryption  Introduce  Bill  to  Break  It 

While  the  senators  do  name  a  few  instances  in  which  encryption  made  it  harder  for 
the  cops  to  investigate  shootings  and  organized  crime,  they  also  chose  the  well- 
trodden  path  of  waving  their  arms  and  scream  about  terrorism  and  protecting 
children,  while  blaming  tech  companies  for  not  doing  enough. 

https://www.vice.com/en  us/article/v3z3z7/republican-encryption-bill-privacv-signal 
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Ransomware  perspectives:  The  shape  of  things  to  come  -  Interview  with  CISO 
Mike  Hamilton 

Mike  Hamilton,  CISO  of  Cl  Security,  discusses  ransomware  attacks  and  offers 
insight  on  how  to  strengthen  the  cybersecurity  program  to  defend  against  new  TTPs 
by  threat  actors.  Mike  discusses  the  impacts  ransomware  attacks  have  on  cities  and 
how  properly  staffing  up  on  InfoSec  talent  is  critical  to  managing  ransomware  risks. 
“Your  monitoring  must  be  comprehensive,  and  someone  must  be  assigned  to  follow 
up  and  investigate  security  alerts,”  notes  Mike.  “Without  proper  people  resourcing, 
your  technology  is  yelling  into  the  wind.  Ask  Target  how  this  works  out.” 

https://www.helpnetsecuritv.com/2020/06/24/ransomware-perspectives/ 


New  WastedLocker  ransomware  demands  payments  of  millions  of  USD 

In  an  interview  with  ZDNet  earlier  today,  Fox-IT  says  they've  been  tracking  the  use  of 
this  new  ransomware  family  since  May  2020.  They  say  the  ransomware  has  been 
exclusively  deployed  against  US  companies.  "Ransom  demands  that  are  asked  by 


Evil  Corp  are  now  typically  into  the  millions,"  Maarten  van  Dantzig,  Fox-IT  security 
researcher,  told  ZDNet  today.  "We've  seen  demands  of  more  than  $10  million,"  he 
added.  [...]  "Typically,  they  hit  file  servers,  database  services,  virtual  machines,  and 
cloud  environments,"  researchers  said. 

https://www.zdnet.com/article/new-wastedlocker-ransomware-demands-pavments- 

of-millions-of-usd/ 


Fxmsp  hackers  made  $1.5M  selling  access  to  corporate  networks 

Fxmsp  became  widely  known  outside  hacker  forums  about  a  year  ago  when 
cybersecurity  boutique  Advanced  Intelligence  (Advlntel)  published  a  series  of  reports 
on  the  actor’s  attempts  to  close  a  $300,000  deal  for  selling  access  to  networks 
belonging  to  Symantec,  Trend  Micro,  and  McAfee.  [...]  According  to  Yelisey 
Boguslavskiy,  Advlntel  director  of  security  research,  Fxmsp  was  the  hacking  part  of  a 
crew  (GPTitan)  consisting  of  specialists  "geared  to  secretly  work  in  financial 
environments"  to  steal  from  high-profile  networks  data  relevant  to  customers. 

https://www.bleepingcomputer.com/news/security/fxmsp-hackers-made-15m-selling- 

access-to-corporate-networks/ 


Bungled  Lancet  study  casts  shadow  over  health  data  industry 

The  ensuing  scandal  threw  a  damper  on  the  idea  of  medical  research  being  based 
entirely  on  big  sets  of  health  data,  at  a  time  when  the  market  for  health  data  is 
booming  and  big  industrial  players  are  pushing  for  its  use  in  medical  research. 
Google  this  week  formally  notified  the  European  Commission  of  its  plans  to  buy 
wearable  health  tracking  devices  company  Fitbit  —  and  its  troves  of  sensitive  health 
data  —  in  a  deal  that  has  alarmed  privacy  campaigners,  while  Palantir,  a  U.S.  data 
mining  company,  recently  gained  access  to  U.K.  health  data. 

https://www.politico.com/news/2020/06/24/lancet-studv-hvdroxychloroguine-health- 

data-industry-337663 


3  Key  Ways  to  Bolster  Healthcare  Cybersecurity  with  MFA,  Training 

For  the  healthcare  sector,  already  burdened  with  the  Coronavirus  response,  the 


expanded  threat  landscape  could  lead  to  some  serious  issues  down  the  line. 
Fortunately,  the  majority  of  these  advisories  contain  key  elements  that  could  allow 
enterprises  to  effectively  close  some  of  these  critical  gaps. 

MULTI-FACTOR  AUTHENTICATION 

USER  EDUCATION,  TRAINING 

ASSET  INVENTORY  AND  PATCH  MANAGEMENT 

https://healthitsecuritv.com/news/3-kev-wavs-to-bolster-healthcare-cvbersecuritv- 

with-mfa-training 


CISA’s  Ware  Runs  Down  COVID-19  Cyber  Threats  to  Health  Sectors 

Despite  the  massive  turn  to  telework  at  government  agencies  and  in  the  private 
sector  during  the  pandemic  -  and  the  accompanying  assault  of  cyber  attacks  from 
actors  looking  to  take  advantage  of  the  situation  -  Ware  said  that  CISA  has 
continued  on  pace  with  other  missions,  including  effort  to  secure  the  national 
elections  in  November.  He  said  the  “risk  picture”  for  CISA  has  shown  up  strongly  in 
four  categories:  phishing  exploit  increases;  ransomware  attacks  on  healthcare 
systems;  espionage  against  pharmaceutical  companies  and  laboratories;  and  risks 
involved  with  shift  to  telework. 

https://www.meritalk.com/articles/cisas-ware-runs-down-covid-19-cvber-threats-to- 

health-sectors/ 


Indiabulls  Group  hit  by  CLOP  Ransomware,  gets  24h  leak  deadline 

"The  Indiabulls  Group  is  a  diversified  financial  services  group  with  interests  in 
housing  finance,  consumer  finance  and  personal  wealth.  The  Group  also  has  a 
presence  in  Real  Estate,  Pharmaceuticals,  Lighting  and  Infrastructure  &  Construction 
Equipment  Leasing[.]"  [...]  Cyberintelligence  firm  Bad  Packets  told 
BleepingComputer,  though,  that  Indiabulls  has  an  Citrix  Netscaler  ADC  VPN 
gateway  exposed,  which  is  vulnerable  to  the  CVE-201 9-1 9781  vulnerability. 

https://www.bleepingcomputer.com/news/security/indiabulls-group-hit-bv-clop- 

ransomware-gets-24h-leak-deadline/ 


FBI,  DoJ  Officials  Warn  of  Common  COVID-19  Cyber  Threat  Vectors 

Tonya  Ugoretz,  deputy  assistant  director  of  the  FBI’s  Cyber  Division,  reported  that 
the  agency’s  Internet  Crime  Complaint  Center  has  seen  as  many  complaints  as  this 
point  in  2020  as  they  did  in  all  of  2019.  Of  those  complaints,  she  said  at  the  June  24 
Fal.Con  for  the  Public  Sector  CrowdStrike  Cybersecurity  Conference,  at  least  20,000 
have  been  about  COVID-19  related  schemes. 

https://www.meritalk.com/articles/fbi-doi-officials-warn-of-common-covid-19-cvber- 

threat-vectors/ 


Banks  can  ill  afford  to  get  complacent  about  coronavirus 

[Cyber]  resiliency  in  a  business  continuity  model  is  going  to  be  crucial  to  ensuring  a 
safe  and  secure  financial  system.  Cyber  resiliency  is  broader  than  the  traditional 
business  continuity  focus  on  data  backup  and  recovery.  It’s  about  data  integrity  and 
the  ability  to  trust  the  data  to  know  with  confidence  that  backed-up  data  has  not  been 
corrupted  or  altered  by  a  cyberattack.  Resilience  is  the  ability  to  operate,  even  in  a 
degraded  state,  and  recover  from  deliberate  attacks. 

https://www.americanbanker.com/opinion/banks-can-ill-afford-to-get-complacent- 

about-coronavirus 


There’s  No  Vaccine  For  Data  Leaks:  Why  One  Cyber  Attack  Leads  To  Another 

Businesses  have  become  far  too  accustomed  to  massive  security  breaches, 
disregarding  them  like  the  common  cold.  Often,  the  remedy  appears  to  be  free  credit 
monitoring  for  the  affected.  But  the  real  threat  is  lost  in  that  perception  of  safety  and 
a  healthy  bounce-back.  Many  significant  risks  are  escalated  after  a  breach 
leveraging  the  data  that  is  lost  in  these  incidents  —  stolen  personal  details  enable 
ransomware  or  “man-in-the-middle”  breaches  to  be  more  targeted  and  effective. 

https://www.forbes.com/sites/emilsavegh/2020/06/24/theres-no-vaccine-for-data- 

Ieaks-why-one-cvber-attack-leads-to-another/#58d58a757300 


Senate  wants  more  clarity  on  cyber  ops 

In  its  version  of  the  annual  defense  policy  bill  — which  passed  the  committee  last 
week,  though  full  text  of  the  language  was  only  made  public  this  week  —  the 
committee  takes  aim  at  U.S.  Cyber  Command’s  so-called  hunt  forward  operations. 
Hunt  forward  operations  involve  teams  from  Cyber  Command  physically  deploying  to 
other  nations  to  assist  them  with  cyber  defense.  These  operations  provide  American 
cyber  teams  insight  into  tactics  that  could  be  turned  against  U.S.  networks  or  used  to 
disrupt  the  elections  process,  officials  have  maintained. 

https://www.fifthdomain.com/congress/2020/Q6/24/senate-wants-more-claritv-on- 

cyber-ops  / 


Cyber  attack  on  Israeli  water-treatment  plant  is  one  indication  of  a  rising  tide  of 
cyber  security  issues 

The  water  facility  attack  was  to  release  large  amounts  of  poisonous  chlorine  into 
Israel’s  water  delivery  infrastructure,  potentially  poisoning  tens  of  thousands  of 
Israelis.  It  may  indicate  a  growing  threat  of  cyber  attack  throughout  the  world. 

FireEye,  a  publicly  traded  cyber  security  company  in  Milpitas,  California,  determined 
that  the  malware  developed  for  this  kind  of  attack  came  out  of  Russia  and 
specifically  from  the  Central  Scientific  Research  Institute  of  Chemistry  and 
Mechanics,  a  Russian  government-owned  technical  research  institution  in  Moscow. 

https://www.militarvaerospace.com/trusted-computinq/article/14178333/cvber- 

security-growing-threat-international-actors 


China  is  Retooling,  and  Russia  Seeks  Harm  to  Critical  Infrastructure 

China  and  Russia  continue  to  pose  the  greatest  espionage  and  cyber  attack  threats 
to  the  United  States,  but  the  intelligence  leader  anticipates  that  other  adversaries 
and  strategic  competitors  will  also  build  and  integrate  cyber  espionage,  cyber  attacks 
and  influence  operations  into  how  they  conduct  business.  “Our  strategic  competitors 
will  increasingly  use  cyber  space  capabilities  including  cyber  espionage,  cyber  attack 
and  continued  influence  operations  to  seek  political,  economic  and  military 
advantage  over  the  United  States,  our  allies  and  our  partners,”  he  said.  “This  is  not 
an  ‘if,’  it  is  a  yes.  They  are  doing  it  and  they  will  continue.” 


https://www.afcea.org/content/china-retooling-and-russia-seeks-harm-critical- 

infrastructure 


Police  arrested  wrong  man  based  on  facial  recognition  fail,  ACLU  says 

The  American  Civil  Liberties  Union  filed  the  complaint  (PDF)  Wednesday  on  behalf 
of  Robert  Williams,  a  Michigan  man  who  was  arrested  in  January  based  on  a  false 
positive  generated  by  facial  recognition  software.  "At  every  step,  DPD's  conduct  has 
been  improper,"  the  complaint  alleges.  "It  unthinkingly  relied  on  flawed  and  racist 
facial  recognition  technology  without  taking  reasonable  measures  to  verify  the 
information  being  provided"  as  part  of  a  "shoddy  and  incomplete  investigation." 

https://arstechnica.com/tech-policv/2020/06/police-arrested-wrong-man-based-on- 

facial-recognition-fail-aclu-savs/ 


Twitter  bans  DDoSecrets  account  over  'BlueLeaks'  police  data  dump 

On  Friday,  last  week,  the  group  published  296  GB  of  data  they  claimed  to  have 
received  from  the  Anonymous  hacker  collective.  The  data  dump,  dubbed  BlueLeaks, 
contained  millions  of  documents  that  were  stolen  from  a  Texas  company  named 
Netsential  that  provided  web  hosting  services  for  various  US  law  enforcement 
entities.  Subsequent  analysis  revealed  that  the  BlueLeaks  data  dump  contained  files 
from  more  than  200  US  police  departments,  fusion  centers,  and  other  law 
enforcement  training  and  support  portals. 

https://www.zdnet.com/article/twitter-bans-ddosecrets-account-over-blueleaks-police- 

data-dump/ 


Self-Propagating  Lucifer  Malware  Targets  Windows  Systems 

The  never-before-seen  malware  initially  tries  to  infect  PCs  by  bombarding  them  with 
exploits  in  hopes  of  taking  advantage  of  an  “exhaustive”  list  of  unpatched 
vulnerabilities.  While  patches  for  all  the  critical  and  high-severity  bugs  exist,  the 
various  companies  impacted  by  the  malware  had  not  applied  the  fixes.  [...]  The 
vulnerabilities  targeted  by  Lucifer  include  Rejetto  HTTP  File  Server  (CVE-2014- 
6287),  Oracle  Weblogic  (CVE-201 7-1 0271),  ThinkPHP  RCE  (CVE-20 18-20062), 
Apache  Struts  (CVE-201 7-9791),  Laravel  framework  CVE-201 9-9081),  and 


Microsoft  Windows  (CVE-20 17-0 144,  CVE-201 7-0145,  and  CVE-2 01 7-8464). 

https://threatpost.com/self-propagating-lucifer-malware-targets-windows- 

svstems/1 56883/ 


Republicans  Who  Don’t  Understand  Encryption  Introduce  Bill  to  Break  It 

While  the  senators  do  name  a  few  instances  in  which  encryption  made  it  harder  for 
the  cops  to  investigate  shootings  and  organized  crime,  they  also  chose  the  well- 
trodden  path  of  waving  their  arms  and  scream  about  terrorism  and  protecting 
children,  while  blaming  tech  companies  for  not  doing  enough. 

https://www.vice.com/en  us/article/v3z3z7/republican-encryption-bill-privacv-signal 
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Your  weekly  briefing  on  Application  Security,  AI  and  Cybercrime: 
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Application  Penetration  Testing 


Modern-day  application  penetration  testing  (or  pentesting)  spans  from  traditional  web 
and  mobile  app  penetration  testing  to  emerging  loT  and  blockchain  penetration  testing. 


Automated  penetration  testing  services  and  SaaS  solutions  incrementally  substitute 
traditional  human-driven  penetration  testing,  providing  greater  scalability,  efficiency  and 
efficiency  and  DevSecOps  integrations  if  implemented  and  conducted  correct 


Attack  Surface  Management 

Attack  Surface  Management  (ASM)  is  composed  of  continuous  discovery,  inventory, 
classification,  prioritization  and  security  monitoring  of  external  digital  assets  that  contain, 
transmit  or  process  your  corporate  data. 


Dark  Web  Monitoring  Surface,  Deep  and  Dark  Web  Explained 

Dark  Web  monitoring  enables  organizations  to  stay  ahead  of  cybercriminals  with 
proactive  intelligence  on  data  breaches  impacting  their  internal  systems  and  trusted 
third-parties,  to  timely  respond  to  phishing,  fraud,  Business  Email  Compromise  (BEC) 
attacks  and  Intellectual  Property  infringements. 
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blog,  and  more  to  put  real-time  security  intelligence  at  your  fingertips.  Instantly  prioritize 
alerts,  incidents,  and  vulnerabilities  based  on  real-time  risk  scores  from  the  world’s  largest 
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SUMMARY 


By  the  CyberWire  staff 


Microsoft  continues  to  urge  users  of  its  Exchange  email  servers  to  patch  and  bring  them  up  to 
date.  A  known,  and  it's  worth  emphasizing  patched,  vulnerability  (CVE-2020-0688)  has  been 
under  active  exploitation  by  nation-state  intelligence  services  since  April.  As  ZDNet  asks,  why 
would  any  intelligence  service  worthy  of  its  trenchcoats  (we  paraphrase  and  mix  many 
metaphors)  burn  a  zero-day  when  they  could  just  waltz  in  through  a  known  hole? 

Trustwave  says  it's  found  a  new  malware  family,  "GoldenSpy,"  embedded  in  tax  software 
companies  doing  business  in  China  have  been  required  by  their  Chinese  bank  to  install.  It 
does  the  taxes;  it  also  opens  a  system-level  backdoor. 

A  Malwarebytes  report  describes  how  Magecart  operators  have  improved  their  game.  The 
paycard  skimming  malware  is  now  being  hidden  in  EXIF  metadata  of  image  files.  There  are 
several  criminal  gangs  known  to  use  Magecart.  This  particular  upgrade  appears  to  be  the 
work  of  Magecart  Group  9. 

The  extortionists  who  compromised  Indiabulls  have  made  good  on  their  threat  to  begin 
releasing  data  if  the  company  didn't  pay  the  ransom.  The  Hindustan  Times  reports  that  the 
first  tranche  of  company  information  has  been  leaked. 

Where  do  vulnerabilities  come  from?  Mostly,  according  to  Snyk's  study  of  open-source 
software  security,  from  indirect  dependencies. 

Twitter  may  have  banned  DDoSecrets  after  the  BlueLeaks  information  dump,  but  DDoSecrets 
rejects  what  they  call  the  social  platform's  unexpectedly  "Nixonian"  move,  and  the  group  tells 
WIRED  they'll  be  looking  for  other  venues  in  which  to  post  whatever  they  come  up  with  in  the 
future. 
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By  Rick  Howard,  CSO,  Chief  Analyst,  and  Senior  Fellow,  The  CyberWire 

What  kind  of  cyber  threat  intelligence  program  do  you  have?  Go  to  the  survey,  here,  and 
choose  all  that  apply. 

1 .  What’s  a  cyber  threat  intelligence  program? 


2.  Somebody  in  the  SOC  reads  security  blogs  and  listens  to  the  CyberWire  every  day. 

3.  I  read  security  blogs  and  listen  to  the  CyberWire  every  day. 

4.  We  have  a  dedicated  team  of  intelligence  analysts  who  read  security  blogs  and  listen 
to  the  CyberWire  every  day. 

5.  We  have  a  dedicated  team  of  intelligence  analysts  who  follow  the  standard 
intelligence  lifecycle  intelligence  process. 
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security  to  your  remote  employees.  Learn  more  about  these  offers 
at  mcafee.com/workfromhome. 
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from  Google  and  Lauren  Zabierek  from  Harvard’s  Belford  Center  on  the  #Sharethemicincyber 
event.  Later,  we  talk  with  Richard  Clarke  and  Robert  Knake,  authors  of  The  Fifth  Domain. 
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CYBERWIRE 

loT  Integrator  Summit:  Securing  Edge  Computing  (Online,  July  14  -  16,  2020)  A  virtual 
summit  to  help  loT  Integrators  learn  more  about  advances  and  updates  in  loT  security  and 
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17,  2020)  The  world’s  leading  cybersecurity  event  is  going  virtual  15-17  July.  Join  your  peers 
and  industry  experts  for  three  days  of  insights.  Watch  over  50  sessions  live  during  Singapore 
business  hours — or  stream  them  later.  Register  today  for  free. 
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hacking... 

Anonymous  Activism  Through  Cyberspace-  2020  Ventures  (Modern  Diplomacy)  In 
between  the  hullabaloo  of  Corona  pandemic,  the  distinct  issues  in  cyberspace  are  anticipated 
to  rise... 
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Patch  time!  NVIDIA  fixes  kernel  driver  holes  on  Windows  and  Linux  (Naked  Security) 
Kernel  driver  bugs  often  let  crooks  take  over  your  entire  system  from  even  the  weediest 
foothold. 

TikTok  to  stop  snooping  on  users'  clipboards  after  iPhone  update  shows  app 

constantly  reads  copied  text  (The  Telegraph)  A  security  patch  from  Apple  has  suddenly 
exposed  just  how  many  smartphone  apps  are  reading  users'  clipboards... 

macOS  Big  Sur  vs  Catalina:  Will  it  be  worth  the  upgrade?  (Macworld  UK)  There  is  change 
coming  both  on  the  surface  and  underneath,  but  will  that  be  enough  to  upgrade  to  Big... 

Cyber  Trends 

Sponsored  content:  What  treadmills  tell  us  about  the  state  of  the  office  during  Covid- 

19.  (The  CyberWire)  (This  article  was  contributed  and  sponsored  by  Extrahop.)  Everything 
from  IP  phones  to  printers  to  treadmills... 

Hospitals  Scramble  to  Adapt  Security  Measures  Amid  Cyberattacks  (Wall  Street  Journal) 
Hackers  are  attempting  to  gain  access  to  hospital  financial  networks  and  medical  records  on  a 
huge  scale,... 

NetMotion  finds  that  remote  employees  are  dangerously  exposed  to  risky  content 

(NetMotion  Software)  NetMotion  used  anonymized  data  to  see  whether  remote  workers  put 
themselves  at  risk  by  clicking  on  risky... 
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The  10  biggest  cyber  security  acquisitions  of  2020  (so  far)  (CRN  A  leg  up  on  the 
competition 

HelpSystems  Acquires  Leading  Data  Classification  Providers  to  Bolster  Security 

Business  (HelpSystems)  Canada-based  Titus  and  UK-based  Boldon  James  join  to  create  top 
platform  in  data  classification  software... 


Qinetiq  disposes  of  Boldon  James  (BOLSAMANIA)  Science  and  engineering  group  Qinetiq 
agreed  to  dispose  of  software  company  Boldon  James  on  Thursday. 

Find  MORE  on  our  website. 

Products,  Services,  and  Solutions 

KnowBe4’s  New  CEO  Fraud  Prevention  Manual  Now  Available  (GlobeNewswire)  Manual 
to  help  security  professionals  stay  better  protected  from  CEO  fraud 

Veea  Brings  Enterprise-Grade  Security  to  SMB/SMEs  and  loT  with  New  vTPN  Security 

Edge  Service  (PR  Newswire)  Veea  Inc.,  a  pioneer  in  smart  edge  connectivity  and  computing, 
today  announced  the  availability  of  their... 

King  &  Union  and  DarkOwl  Unite  to  Provide  Fractional  Access  to  Searchable  Darknet 

Data  (King  &  Union)  DarkOwl  Brings  World’s  Largest  Database  of  Darknet  Content  to  King  & 
Union  Avalon  Cyber  Analysis  Platform... 

Find  MORE  on  our  website. 
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SOAR  Is  DevSecOps  (RSA  Conference)  In  2016,  I  was  convinced  that  DevSecOps  was  the 
way  forward  for  the  network  defenders  of  the  world  to... 

Core  cybersecurity  principles  for  new  companies  and  products  (Help  Net  Security)  A 
new  World  Economic  Forum  report  outlines  core  cybersecurity  principles  and  points  to  how 
companies... 

There  is  no  cybersecurity  silver  bullet  (TechRadar  There's  no  single  cybersecurity  solution 
Find  MORE  on  our  website. 
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Facebook  will  show  users  a  pop-up  warning  before  they  share  an  outdated  story 

(TechCrunch)  Facebook  announced  Thursday  that  it  would  introduce  a  notification  screen 
warning  users  if  they  try  to... 

Marred  by  garbage:  Striking  a  balance  for  security  data  (Help  Net  Security)  One  of  the 
most  central  questions,  is  how  much  data  is  enough?  What  is  the  correct  balance?  Niagara 
Network... 

Research  and  Development 

Quantum  entanglement  demonstrated  aboard  orbiting  CubeSat:  Advance  poised  to 

enable  cost-effective  space-based  global  quantum  network  for  secure  communications 

and  more  (ScienceDaily)  In  a  critical  step  toward  creating  a  global  quantum  communications 
network,  researchers  have  generated... 
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Madura's  regime  made  Venezuela  the  country  with  the  largest  presence  of  cyber  troops 
dedicated... 

Bid  to  keep  Huawei  out  of  5G  trials  (Telegraph)  DoT  panel  to  review  participation  of 
Chinese  companies 

Japan  Plans  National  Champion  to  Challenge  Huawei  (Wall  Street  Journal)  Japan’s  top 
telecommunications  company  is  taking  a  $600  million  stake  in  a  leading  telecoms  hardware... 
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The  Law  of  Classified  Information:  A  Primer  (Lawfare)  How  the  U.S.  government  regulates 
its  secrets. 
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Justice  Department  today  criminally  charged  a  Canadian  and  a  Northern  Ireland  man  for 
allegedly... 

Find  MORE  on  our  website. 
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TOP  NEWS 


Florida  Officers  Lured  Into  Ambush 
Attack  at  Call  for  Service 

Several  officers  with  the  Tampa  (LF)  Police 
Department  were  reportedly  ambushed  early 
Saturday  morning  while  responding  to  a  call  for 
service. 


READ  MORE 


Three  North  Carolina  Officers  Fired 
Over  Hate  Speech 


Piner  reportedly  said  he  is  “ready”  for  the  civil  war 
and  martial  law  he  believes  is  coming,  saying,  “we 
are  just  gonna  go  out  and  start  slaughtering  them...' 


READ  MORE 


Minneapolis  Takes  First  Steps  Toward  Disbanding  Police 
Department 

The  head  of  the  new  department  would  be  somebody  with  "non-law-enforcement 
experience  in  community  safety  services,  including  but  not  limited  to  public  health 
and/or  restorative  justice  approaches." 

READ  MORE 


NYPD  Officers  May  be  Planning  July  4  Strike,  NY  Post 
Reports 

The  paper  says  a  pair  of  flyers  making  the  rounds  among  NYPD  officers  are 
encouraging  them  to  call  out  sick  July  4.  “NYPD  cops  will  strike  on  July  4th  to  let  the 
city  have  their  independence  without  cops,”  the  message,  which  is  being  passed 
among  cops  via  text,  according  to  Post  sources. 

READ  MORE 


New  Jersey  Trooper  Thrown  from 
Patrol  Vehicle  in  Horrific  Crash 

A  trooper  with  the  New  Jersey  State  Police  trooper 


■  was  thrown  30  feet  from  his  patrol  vehicle  in  a  vehicle 
collision  with  a  dump  truck  Monday  on  the  New 
Jersey  Turnpike. 

READ  MORE 


Rasmussen  Poll:  Majority  of  Americans  Want  to  Keep 
Police 

A  recent  poll  conducted  by  Rasmussen  indicates  that  Americans  value  the  role  of  the 
police  and  worry  that  increasing  criticism  of  cops  will  make  their  communities  less 
safe. 

READ  MORE 


Pennsylvania  Man  Pulls  Police 
Officer  from  Wrecked  Patrol  Car 

Daylan  McLee  was  at  a  Fathers'  Day  event  with 


family  when  he  saw  the  police  officer  pinned  to  the 
ground  by  his  patrol  vehicle  following  a  crash. 


READ  MORE 


Senate  Democrats  Torpedo  GOP's 
Police  Reform  Bill 

On  one  major  point  of  dissension  between  the 
parties,  the  Republican  bill  leaves  intact  the  “qualified 
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A  request  has  been  assigned  to  you:  FOIA  Request  /  R009142-062920 

FOIA  Request  for  Records 
Assigned  Staff:  Eryn  Hedderman 
Status:  Received 
Create  Date:  June  29,  2020 
Due  Date:  July  06,  2020 
Name  of  Requester:  Emma  Best 
Requester  Affiliation:  Press 

Record(s)  Requested:  To  Whom  It  May  Concern:  Pursuant  to  the  Illinois  Freedom  of  Information  Act., 
I  hereby  request  the  following  records:  1.  Documents  mentioning,  describing  or  generated  in  response  to 
the  BlueLeaks  release,  the  preceding  hack  or  subsequent  fallout,  including  but  not  limited  to:  *  Damage 
assessments  *  Emails  *  Interagency  communications  (local,  state,  or  federal)  *  Communications  with 
the  press  about  BlueLeaks  *  Communications  with  Twitter  or  other  social  media  or  sharing  platforms  2. 
Documents  mentioning  or  describing  Distributed  Denial  of  Secrets  (DDoSecrets)  You  may  limit  this 
request  to  records  generated  between  November  1,  2018  and  the  present.  I  am  a  member  of  the  news 
media  and  request  classification  as  such.  I  have  previously  written  about  the  government  and  its 
activities,  with  some  reaching  over  100,000  readers  in  outlets  such  as  Gizmodo,  MuckRock, 
Motherboard,  Property  of  the  People,  Unicorn  Riot,  and  The  Outline,  among  others.  As  such,  as  I  have  a 
reasonable  expectation  of  publication  and  my  editorial  and  writing  skills  are  well  established.  In 
addition,  I  discuss  and  comment  on  the  files  online  and  make  them  available  through  non-profits  such  as 
the  library  Internet  Archive  and  the  journalist  non-profit  MuckRock,  disseminating  them  to  a  large 
audience.  While  my  research  is  not  limited  to  this,  a  great  deal  of  it,  including  this,  focuses  on  the 
activities  and  attitudes  of  the  government  itself.  As  such,  it  is  not  necessary  for  me  to  demonstrate  the 
relevance  of  this  particular  subject  in  advance.  As  my  primary  purpose  is  to  inform  about  government 
activities  by  reporting  on  it  and  making  the  raw  data  available,  I  request  that  fees  be  waived.  The 
requested  documents  will  be  made  available  to  the  general  public,  and  this  request  is  not  being  made  for 
commercial  purposes.  In  the  event  that  there  are  fees,  I  would  be  grateful  if  you  would  inform  me  of  the 
total  charges  in  advance  of  fulfilling  my  request.  I  would  prefer  the  request  filled  electronically,  by  e- 
mail  attachment  if  available  or  CD-ROM  if  not.  Thank  you  in  advance  for  your  anticipated  cooperation 
in  this  matter.  I  look  forward  to  receiving  your  response  to  this  request  within  5  business  days,  as  the 
statute  requires.  Sincerely,  Emma  Best  Upload  documents  directly: 

https://https://www.muckrock.comhttps://accounts.muckrock.com/accounts/login/?next=https%3A%2F 

%2Fwww.muckrock.com%2Faccounts%2Flogin%2F%3Fnext%3D%252Faccounts%252Fagency_login 

%252Fcook-county-sheriff-719%252Fblueleaks-cook-county-sheriff- 

9694 1  %252F%253F&url_auth_token=AAAaaJnszUVssmdgx6fh2R- 

tE3U%3AljppAE%3ADWZbgy7n8640ATjAMxtAsPZltYs 


Login  to  the  system  and  view  your  request  by  clicking  HERE.  Your  username  and  password  is  the  same 
as  your  Active  Directory  login,  used  to  access  all  CCSO  computers.  If  you  have  any  questions  or 
concerns  regarding  this  email  notification,  please  contact  the  Legal  Department  at  312-603-6444. 


This  is  an  auto-generated  email  and  has  originated  from  an  unmonitored  email  account.  Please  DO  NOT  REPLY  to 
this  email  as  the  contents  of  your  response  and  any  attachments  may  be  externally  disseminated  inadvertently.  Click 
the  link  above  to  respond  and  upload  documents  for  secure  internal  review. 
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CPIC  <CPIC@chicagopolice.org> 

June  29,  2020  10:22:25  AM  CDT 
June  29,  2020  10:26:07  AM  CDT 

(U--FOUO)  MB  -  Criminal  Hackers  Target  US  Law  Enforcement  Data 
06262020.pdf 


External  Message  Disclaimer 

j  This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when  j 
opening  attachments,  clicking  links,  or  responding  to  this  email. 

ALCON: 

Please  see  attached  product  entitled,  (U//FOUO)  Intelligence  in  Brief:  Criminal  Hackers  Target  US  Law  Enforcement 
Data. 

(U//FOUO)  Intended  Audience:  Federal,  state,  and  local  homeland  security  officials  and  authorized  critical 
infrastructure,  key  resource  personnel,  and  private  sector  security  officials 

Chicago  Police  Department 

Crime  Prevention  and  Information  Center  (CPIC) 

Fusion  Center 

312-745-5669,  Fax  312-745-6927 

THE  CONTENT  OF  THIS  DOCUMENT  MAY  BE  LAW  ENFORCEMENT  SENSITIVE  (LES)  &/OR  FOR  OFFICIAL 
USE  ONLY  (FOUO).  Any  further  disclosure  or  dissemination  of  this  document  or  the  information  contained  herein  is 
strictly  prohibited  without  the  approval  of  the  Chicago  Police  Department's  Crime  Prevention  &  Information  Center. 
Elements  of  this  document  may  be  subject  to  28  CFR  part  23.  Illinois  DL  or  ID  images  are  only  for  use  as  authorized 
by  625  ILCS  5/6-110.1  and  92111.  Adm.  Code  1030.140.  This  information  shall  not  be  released  to  the  media  or  the 
general  public.  FAILURE  TO  ADHERE  TO  THESE  POLICIES  MAY  RESULT  IN  CIVIL,  CRIMINAL  OR 
DISCIPLINARY  ACTION. 

It  should  be  noted  that  some  of  this  information  describes  First  Amendment-protected  activities.  The  Chicago  Police 
Department's  Crime  Prevention  and  Information  Center  (CPIC)  recognizes  that  Americans  have  constitutionally 
protected  rights  to  assemble,  speak,  and  petition  the  government.  The  CPIC  safeguards  these  rights  and  only  reports 
on  First  Amendment-protected  activities  for  operational  planning  in  the  interest  of  assuring  the  safety  and  security  of 
the  demonstrators  and  the  public.  The  CPIC  will  continue  to  communicate  these  events  with  other  law  enforcement 
partners  in  an  effort  to  facilitate  the  Department's  mission  of  assuring  the  safety  and  security  of  the  demonstrators  and 
the  public. 


(U//FOUO)  MB:  Criminal  Hackers  Target  US  Law  Enforcement  Data,  dated  29  June 
2020 _ 


Sent: 

Received: 


June  29,  2020  10:22:25  AM  CDT 
June  29,  2020  10:26:08  AM  CDT 


FW:  UNCLASS//FOUO//LES  -  Various  Documents  -  June  29,  2020  -  Part  III 


Thomas  Tilton  (Emergency  Management)  <Thomas.Tilton@cookcountyil.gov> 

Michael  Brady  (Sheriff)  <Michael.Brady@cookcountyil.gov>,  Robert  Lunk 
(Sheriff)  <Robert. Lunk@cookcountyil.gov> 

June  29,  2020  1 1:21:15  AM  CDT 
June  29,  2020  1 1 :21 :21  AM  CDT 

(U--FOUO)  I  IB  -  Criminal  Hackers  Target  US  Law  Enforcement  Data 
06262020.pdf,  Anarchist  Extremists  -  Antifa.pdf,  Coronavirus  Special  OSINT 
Report -SOR  102-20.pdf,  DMWA200629.pdf,  01  Brief29JUN20.pdf,  Purple 
Notice  1002  -  Concealment  of  cocaine  (United  Kingdom). pdf,  SOUTHCOM 
Security  Bulletin  -  06.27.20.pdf,  SWFO-IN  Taking  the  Red  Pill-  Linguistic 
Indicators  of  Extremist  ldeology.pdf,  USBP  NTC-BP  BOLO  06-27-2020  Glenn 
Murray  VANCIL  (DoD).pdf,  VILT  Schedule  Flyer  -  July  2020.pdf 
Mike  and  Rob,  I  am  on  the  mailing  list  of  this  group  and  I  forward  all  of  this  product  (and  it  is  a  LOT)  everyday  to  our 
OIS  people.  Let  me  know  if  you  guys  like  this.  TT 

From:  Ness,  Michael  <michael.ness@hq.dhs.gov> 

Sent:  Monday,  June  29,  2020  11:15  AM 

To:  Adrian  Cunningham  (Adrian.Cunningham@fema.dhs.gov);  'Adrianne.Michele@socom.mil';  AITES,  KELLIE  A  CIV 
USAF  ACC  55  SFS/S5AT  <kellie.aites@us.af.mil>;  'Allen_Rothbaum@ios.doi.gov';  Anderson,  Matthew  E  LT  USN 
STRATCOM  J34  (USA)  (matthew.e.anderson5.mil@mail.mil)  <matthew.e.anderson5.mil@mail.mil>;  Distler,  Andrew 
(CTR)  <andrew.distler@associates.hq.dhs.gov>;  MARCUS,  ANDREW  <andrew.marcus@hq.dhs.gov>;  Anna  Castillo 
<anna. castillo. l@us.af.mil>;  Brad  Tippit  (Brad.Tippit@Missouricitytx.gov)  <Brad.Tippit@Missouricitytx.gov>; 
'Bruce.Steven.Miller@us.army.mil';  Pelton,  Bryan  (CTR)  <bryan.pelton@associates.hq.dhs.gov>; 
'captain@berwickpolice.org';  Chandra  White  <Chandra.white@us.af.mil>;  Oppliger,  Christopher 
<christopher.oppliger@hq.dhs.gov>;  Cisneros,  Tony  <Tony.Cisneros@fletc.dhs.gov>;  'CLTibbs@co.pg.md.us'; 
ALFORD,  DALE  <dale.alford@hq.dhs.gov>;  'Darryl_Ward@ios.doi.gov';  ATWOOD,  DAVID  (CTR) 
<david.atwood@associates.hq.dhs.gov>;  Davidson,  Jeffrey  <jeffrey.davidson@hq.dhs.gov>;  Delcore,  Robert 
<Robert.Delcore@uscis.dhs.gov>;  Delgado,  Jose  L  <Jose.Delgado@tsa.dhs.gov>; 

'dennis.gonzalez@CityofRochester.gov';  dgirou@arlingtonva.us;  'dgpeterson@lanl.gov';  Schwarzrock,  Don 
<don.schwarzrock@hq.dhs.gov>;  Downey,  Michael  <Michael.Downey@hq.dhs.gov>;  Dzurilla,  Christopher 
<Christopher.Dzurilla@HQ.DHS.GOV>;  Gagnon,  Bruce  P  <Bruce_Gagnon@nps.gov>;  Graves,  Jeremy  W  MSgt  USAF 
AFDW  (USA)  (jeremy.w.graves.mil@mail.mil)  <jeremy.w.graves.mil@mail.mil>;  greg.brock@nlrb.gov;  HARDING, 
DANIEL  <daniel.harding@hq.dhs.gov>;  Harvey,  Timothy  <Timothy.Harvey@fletc.dhs.gov>;  Henry  Rivero: 
<Henry.Rivero@bep.gov>;  'hhgreen@nmic.navy.mil';  Holder,  Richard  <Richard.Holder@HQ.DHS.GOV>;  Hughes, 
Gregory  (CDC/OPHSS/NCHS)  (nvx2@cdc.gov)  <nvx2@cdc.gov>;  Hunter,  Joseph  David  (Joe)  2d  LT  USAF  (US) 
(joseph.d.hunterl6.mil@mail.mil)  <joseph.d.hunterl6.mil@mail.mil>;  CURRIE,  JASON  (CTR) 

<jason.currie@associates.hq.dhs.gov>;  Jeffrey  McClung  <jeffrey.mcclung@jfcc-imd.stratcom.mil>;  Henderson,  Jesse 
K  CTR  <Jesse.K.Henderson@uscg.mil>;  Tadrick,  Joe  <Joe.Tadrick@hq.dhs.gov>;  John  Bamford 
<Jbamford@arlingtonva.us>;  'john.a.kavaliunas.civ@mail.mil';  'John.Glodo@crystal.dia.mil';  'john.leo-l@nasa.gov'; 
Jonesmcgee,  Darius  A  SSgt  USAF  (USA)  (darius.a.jonesmcgee.mil@mail.mil)  <darius.a.jonesmcgee.mil@mail.mil>;  JS 
Pentagon  DoM  Mailbox  JSSO  Military  Security  Force  <js. pentagon. dom.mbx.jsso-military-security-force@mail.mil>; 
kenneth.j.anderson3.civ@mail.mil;  Kristy  KorchakCampbell  (kristy.korchakcampbell@us.af.mil) 
<kristy.korchakcampbell@us.af.mil>;  kristy.korchak-campbell@auab.afcent.af.mil;  'kunichs@guestservices.com'; 
Battiste,  Lawrence  <lawrence.battiste@hq.dhs.gov>;  Lee  Taylor  (Lee.Taylor@hq.dhs.gov);  Linneman,  Eric 
<Eric.linneman@dla.mil>;  Mannix,  Alan  <Alan.Mannix@bep.gov>;  'mark.holloway@ic.fbi.gov';  Marler,  Christopher  F 
SSgt  USAF  (USA)  (christopher.f.marler.mil@mail.mil)  <christopher.f.marler.mil@mail.mil>;  Mascolo,  John 
<John.Mascolo@tsa.dhs.gov>;  'Matthew.f.croson@usdoj.gov';  McBride,  Chip  <chip.mcbride@hq.dhs.gov>;  Michael 
Malcolm  <michael.s.malcolm2.civ@mail.mil>;  Michael  Robinson:  <michael.robinson@bep.gov>; 
'michael.g.copeland2. civ@mail.mil';  Michael.Kenny@bep.gov;  'michael.w.young8. ctr@mail.mil';  Mike  Evans 
<Mike.Evans@calvertcountymd.gov>;  monika.l.junker.civ@mail.mil;  Moreta,  Richard  <richard.moreta@hq.dhs.gov>; 
Nicholas  Paoletti  (nicholas.paoletti.l@us.af.mil)  <nicholas.paoletti.l@us.af.mil>;  'n-nc.peterson.ncj3.mbx.j34-letic- 
omb@mail.mir;  'Odis.Stroud@cookcountyil.gov';  Oppermann,  George  Henry  CIV  USARMY  USAG  (US) 
<george.h.oppermann.civ@mail.mil>;  Ortega,  John  A  CIV  <John.A.Ortega@uscg.mil>;  Booker,  Patrick  M  (N/A) 
<patrick.m.booker@uscis.dhs.gov>;  Patterson,  Richard  V  (Rick)  CTR  STRATCOM  J34  (US) 


From: 

To: 

Sent: 

Received: 

Attachments: 


<richard.v.patterson.ctr@mail.mil>;  Pepin,  Andrew  <Andrew.Pepin@HQ.DHS.GOV>;  Groven,  Philip 
<Philip.Groven@hq.dhs.gov>;  Ping,  William  Darion  <william.d.ping.civ@mail.mil>;  Pinkham,  Lawrence  H  JR  CIV 
STRATCOM  J34  (US)  <lawrence.h. pinkham. civ@mail.mil>;  'PittmanT@state.gov';  POULSEN,  ROBERT  A  2d  Lt  USAF 
ACC  55  ISS/IN  <robert.poulsen@us.af.mil>;  'Raymond.Hankins@nlrb.gov';  Loveless,  Richard 
<richard.loveless@hq.dhs.gov>;  Richard  Reed  <Richard.Reed@firstnet.gov>;  Richard  Swarens 
<Richard.Swarens@whmo.mil>;  'Richard.Cestero@bep.gov';  Roddy,  Gene  E.  CIV  WHMO/HQ. 
<Gene.E.Roddy@whmo.mil>;  Russell,  John  W  MSG  USARMY  JS  DOM  (US)  <john. w.russell36.mil@mail.mil>; 
'russell.r.hicks.civ@mail.mN';  BOYER,  RYAN  <ryan.boyer@hq.dhs.gov>;  'Ryan.Gibson@faa.gov'; 

'Salvatore. ingraldi.civ@mail. mil';  Shell,  Alvin  <alvin.shell@bep.gov>;  Sims,  Karen  <karen.sims@hq.doe.gov>; 
'smithbr@state.gov';  Stephen  J  Barbieri  (stephen.j.barbieri@uscis.dhs.gov);  Stephen  Kunich 
<Stephen.Kunich@pae.com>;  'Stephen.Hutchens@bep.gov';  Steven  Schoen  <steven. m.schoen@lmco.com>; 
Stewart,  Kerry  <Kerry.Stewart@cisa.dhs.gov>;  Stewart,  Kevin  L  CTR  <Kevin.L.Stewart@uscg.mil>; 

'sylvia. c.harris.civ@mail. mil';  Thomas  Klug:  <Thomas.Klug@bep.gov>;  'thomas.a.stroud@nasa.gov'; 
'thomas.loyd@uscp.gov';  'Thomas.Tilton@cookcountyil.gov';  Torian,  William  A  Jr  CIV  USAF  (USA) 
(william.a.torian.civ@mail.mil)  <william. a. torian. civ@mail.mil>;  Versichelli,  Thomas 

<thomas.versichelli.civ@mail.mil>;  Victor  Calloway  <vcalloway@gpo.gov>;  Waage,  Timothy  S  CIV  STRATCOM  J34 
(US)  <timothy.s. waage. civ@mail.mil>;  Waterman,  Ronald  T  CIV  DSS  DSS  ISFO  (US) 

<ronald.t.waterman.civ@mail.mil>;  BERG,  WENDY  <wendy.berg@hq.dhs.gov>;  WERNER,  MATTHEW  R  TSgt  USAF 
AFOSI  55  SFS/Det  204  <matthew.werner.4@us.af.mil>;  Wilemon,  Nicole  <nwilemon@blm.gov>;  DeArcangelis, 
William  <william.dearcangelis@HQ.DHS.GOV>;  Balcerzak,  William  J  <William.J.Balcerzak@uscis.dhs.gov>;  Wilson, 
Randall  Craig  CIV  USARMY  21 SIG  BDE  (USA)  (randall.c.wilsonl2.civ@mail.mil)  <randall.c.wilsonl2.civ@mail.mil>; 
Wolf,  Thomas  John  (Tom)  CIV  USARMY  21  SIG  BDE  (US)  (thomas.j.wolf.civ@mail.mil)  <thomas.j.wolf.civ@mail.mil>; 
Wyman,  Isabel  <isabel.wyman@hq.dhs.gov> 

Subject:  UNCLASS//FOUO//LES  -  Various  Documents  -  June  29,  2020  -  Part  III 


External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 


M  ichtxeb  “Elliot”  Nety 

Program  Manager 

Industrial  Security  Branch  -  CCIPP  Program  Office 
Office  of  Chief  Security  Officer  |  National  Security  Services  Division 
DHS-HQ  Desk:  202-447-5046  |  Mobile  Work  Cell:  202-853-0569 
Email(s):  michael.ness@hq.dhs.gov,  or  OCSO-SARM@hq.dhs.gov 


Homeland 

Security 


"With  honor  and  integrity,  we  will  safeguard  the  American  people,  our  homeland. 


WARNING:  This  document  is  FOR  OFFICIAL  USE  ONLY  (FOUO).  It  is  to  be  controlled,  stored,  handled,  transmitted,  distributed,  and  disposed  of  in  accordance 
with  DHS  policy  relating  to  FOUO  information.  This  information  shall  not  be  distributed  beyond  the  original  addressees  without  prior  authorization  of  the 
originator.  This  communication,  along  with  any  attachments,  is  covered  by  Federal  and  State  law  governing  electronic  communications  and  may  contain 
restricted  and  legally  privileged  information.  If  the  reader  of  this  message  is  not  the  intended  recipient,  you  are  hereby  notified  that  any  dissemination, 
distribution,  use  or  copying  of  this  message  is  strictly  prohibited.  If  you  have  received  this  in  error,  please  reply  immediately  to  the  sender  and  delete  this 
message. 


From:  McIntyre,  Timothy  A  <Timothy.A.  Mclntyre@ice.dhs.gov> 

Sent:  Monday,  June  29,  2020  11:33  AM 

To:  Ness,  Michael  <michael.ness@hq.dhs.gov> 

Subject:  (U/LES)  Information 


Timothy  A.  McIntyre,  USN  CPO  Ret.,  MHS,  CEM,  CHS  III 
Security  Specialist 

U.S.  Department  of  Homeland  Security 
U.S.  Immigration  and  Customs  Enforcement 
Badge  &  Credential  Program 
One  East  Broad  Street,  Suite  200 
Bethlehem,  PA.  18018-5913 
Office:  (610)  861-8520  -  Ext  107 
Cell:  (202)  277-2078 
Fax:  (610)  861-8525 


(U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 


From: 

To: 

Sent: 

Received: 

Attachments: 


ISP.DoNotReply  <ISP.DoNotReply@lllinois.gov> 

Paul  Villanueva  <paul.villanueva@cookcountyil.gov>,  Paul  Villanueva  (Sheriff) 
<Paul.Villanueva@cookcountyil.gov> 

June  29,  2020  3:12:35  PM  CDT 
June  29,  2020  3:16:59  PM  CDT 

(U--FOUO)  MB  -  Criminal  Flackers  Target  US  Law  Enforcement  Data 
06262020.pdf 


External  Message  Disclaimer 


j  This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when  j 
opening  attachments,  clicking  links,  or  responding  to  this  email. 

The  following  information  is  being  disseminated  by  STIC  to  our  email  distribution  list  for  situational 

awareness  purposes.  Replies  can  be  sent  to  stic@illinois.gov. 

Good  afternoon, 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated  June  29, 
2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a  hack-and-leak 
operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support  of  or  in  response  to 
nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years  of  data  from  200  police 
departments,  fusion  centers,  and  other  law  enforcement  training  and  support  resources  around  the  globe,  according 
to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack-and-leak  activity  against  the  Russian 
Government. 

This  intelligence  information  is  being  passed  through  as  a  courtesy  to  the  originating  agency.  The  STIC  had  no  part  in 
developing  this  information  and  has  not  verified  the  contents  to  be  factual.  If  you  have  any  questions  reference  this 
information  please  contact  the  originating  agency.  Please  ensure  the  Data  Security  designation  on  this  document  is 
adhered  to.  Do  not  advise  individuals  contained  therein  of  this  alert.  Persons  or  organizations  violating  distribution 
restrictions  will  be  prohibited  from  receiving  future  documents  and  will  be  removed  from  distribution  lists.  NO 
REPORT  OR  SEGMENT  THEREOF  MAY  BE  RELEASED  TO  ANY  MEDIA  SOURCES.  Please  contact  STIC  at  877-455-7842  if 
you  have  any  questions  or  need  additional  information. 


(U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 


From: 

To: 

Sent: 

Received: 

Attachments: 


ISP.DoNotReply  <ISP.DoNotReply@lllinois.gov> 

Patrick  Moriarty  <Patrick. moriarty@cookcountyil.gov>,  Patrick  Moriarty 
(Sheriff)  <Patrick. Moriarty@cookcountyil.gov> 

June  29,  2020  3:12:35  PM  CDT 
June  29,  2020  3:17:17  PM  CDT 

(U--FOUO)  I  IB  -  Criminal  Flackers  Target  US  Law  Enforcement  Data 
06262020.pdf 


External  Message  Disclaimer 


j  This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when  j 
opening  attachments,  clicking  links,  or  responding  to  this  email. 

The  following  information  is  being  disseminated  by  STIC  to  our  email  distribution  list  for  situational 

awareness  purposes.  Replies  can  be  sent  to  stic@illinois.gov. 

Good  afternoon, 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated  June  29, 
2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a  hack-and-leak 
operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support  of  or  in  response  to 
nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years  of  data  from  200  police 
departments,  fusion  centers,  and  other  law  enforcement  training  and  support  resources  around  the  globe,  according 
to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack-and-leak  activity  against  the  Russian 
Government. 

This  intelligence  information  is  being  passed  through  as  a  courtesy  to  the  originating  agency.  The  STIC  had  no  part  in 
developing  this  information  and  has  not  verified  the  contents  to  be  factual.  If  you  have  any  questions  reference  this 
information  please  contact  the  originating  agency.  Please  ensure  the  Data  Security  designation  on  this  document  is 
adhered  to.  Do  not  advise  individuals  contained  therein  of  this  alert.  Persons  or  organizations  violating  distribution 
restrictions  will  be  prohibited  from  receiving  future  documents  and  will  be  removed  from  distribution  lists.  NO 
REPORT  OR  SEGMENT  THEREOF  MAY  BE  RELEASED  TO  ANY  MEDIA  SOURCES.  Please  contact  STIC  at  877-455-7842  if 
you  have  any  questions  or  need  additional  information. 


(U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 


From: 

To: 

Sent: 

Received: 

Attachments: 


ISP.DoNotReply  <ISP.DoNotReply@lllinois.gov> 

Adam  Murphy  <adam.murphy@cookcountyil.gov>,  Adam  Murphy  (Sheriff) 
<Adam .  Mu  rphy@cookcountyil  ,gov> 

June  29,  2020  3:12:35  PM  CDT 
June  29,  2020  3:16:27  PM  CDT 

(U--FOUO)  I  IB  -  Criminal  Flackers  Target  US  Law  Enforcement  Data 
06262020.pdf 


External  Message  Disclaimer 


j  This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when  j 
opening  attachments,  clicking  links,  or  responding  to  this  email. 

The  following  information  is  being  disseminated  by  STIC  to  our  email  distribution  list  for  situational 

awareness  purposes.  Replies  can  be  sent  to  stic@illinois.gov. 

Good  afternoon, 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated  June  29, 
2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a  hack-and-leak 
operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support  of  or  in  response  to 
nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years  of  data  from  200  police 
departments,  fusion  centers,  and  other  law  enforcement  training  and  support  resources  around  the  globe,  according 
to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack-and-leak  activity  against  the  Russian 
Government. 

This  intelligence  information  is  being  passed  through  as  a  courtesy  to  the  originating  agency.  The  STIC  had  no  part  in 
developing  this  information  and  has  not  verified  the  contents  to  be  factual.  If  you  have  any  questions  reference  this 
information  please  contact  the  originating  agency.  Please  ensure  the  Data  Security  designation  on  this  document  is 
adhered  to.  Do  not  advise  individuals  contained  therein  of  this  alert.  Persons  or  organizations  violating  distribution 
restrictions  will  be  prohibited  from  receiving  future  documents  and  will  be  removed  from  distribution  lists.  NO 
REPORT  OR  SEGMENT  THEREOF  MAY  BE  RELEASED  TO  ANY  MEDIA  SOURCES.  Please  contact  STIC  at  877-455-7842  if 
you  have  any  questions  or  need  additional  information. 


(U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 


From: 

To: 

Sent: 

Received: 

Attachments: 


ISP.DoNotReply  <ISP.DoNotReply@lllinois.gov> 

Phillip  D  Mackey  <Phillip.mackey@cookcountyil.gov>,  Phillip  Mackey  (Sheriff) 
<Phillip.Mackey@cookcountyil.gov> 

June  29,  2020  3:12:35  PM  CDT 
June  29,  2020  3:16:15  PM  CDT 

(U--FOUO)  I  IB  -  Criminal  Flackers  Target  US  Law  Enforcement  Data 
06262020.pdf 


External  Message  Disclaimer 


j  This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when  j 
opening  attachments,  clicking  links,  or  responding  to  this  email. 

The  following  information  is  being  disseminated  by  STIC  to  our  email  distribution  list  for  situational 

awareness  purposes.  Replies  can  be  sent  to  stic@illinois.gov. 

Good  afternoon, 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated  June  29, 
2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a  hack-and-leak 
operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support  of  or  in  response  to 
nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years  of  data  from  200  police 
departments,  fusion  centers,  and  other  law  enforcement  training  and  support  resources  around  the  globe,  according 
to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack-and-leak  activity  against  the  Russian 
Government. 

This  intelligence  information  is  being  passed  through  as  a  courtesy  to  the  originating  agency.  The  STIC  had  no  part  in 
developing  this  information  and  has  not  verified  the  contents  to  be  factual.  If  you  have  any  questions  reference  this 
information  please  contact  the  originating  agency.  Please  ensure  the  Data  Security  designation  on  this  document  is 
adhered  to.  Do  not  advise  individuals  contained  therein  of  this  alert.  Persons  or  organizations  violating  distribution 
restrictions  will  be  prohibited  from  receiving  future  documents  and  will  be  removed  from  distribution  lists.  NO 
REPORT  OR  SEGMENT  THEREOF  MAY  BE  RELEASED  TO  ANY  MEDIA  SOURCES.  Please  contact  STIC  at  877-455-7842  if 
you  have  any  questions  or  need  additional  information. 


(U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 


From: 

To: 

Sent: 

Received: 

Attachments: 


ISP.DoNotReply  <ISP.DoNotReply@lllinois.gov> 

Kathleen  Urbanczyk  <ccso.intel@cookcountyil.gov>,  CCSO  Intel  (Sheriff) 
<CCSO. INTEL@cookcountyil.gov> 

June  29,  2020  3:12:35  PM  CDT 
June  29,  2020  3:19:50  PM  CDT 

(U--FOUO)  MB  -  Criminal  Hackers  Target  US  Law  Enforcement  Data 
06262020.pdf 


External  Message  Disclaimer 


j  This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when  j 
opening  attachments,  clicking  links,  or  responding  to  this  email. 

The  following  information  is  being  disseminated  by  STIC  to  our  email  distribution  list  for  situational 

awareness  purposes.  Replies  can  be  sent  to  stic@illinois.gov. 

Good  afternoon, 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated  June  29, 
2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a  hack-and-leak 
operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support  of  or  in  response  to 
nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years  of  data  from  200  police 
departments,  fusion  centers,  and  other  law  enforcement  training  and  support  resources  around  the  globe,  according 
to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack-and-leak  activity  against  the  Russian 
Government. 

This  intelligence  information  is  being  passed  through  as  a  courtesy  to  the  originating  agency.  The  STIC  had  no  part  in 
developing  this  information  and  has  not  verified  the  contents  to  be  factual.  If  you  have  any  questions  reference  this 
information  please  contact  the  originating  agency.  Please  ensure  the  Data  Security  designation  on  this  document  is 
adhered  to.  Do  not  advise  individuals  contained  therein  of  this  alert.  Persons  or  organizations  violating  distribution 
restrictions  will  be  prohibited  from  receiving  future  documents  and  will  be  removed  from  distribution  lists.  NO 
REPORT  OR  SEGMENT  THEREOF  MAY  BE  RELEASED  TO  ANY  MEDIA  SOURCES.  Please  contact  STIC  at  877-455-7842  if 
you  have  any  questions  or  need  additional  information. 
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Good  afternoon, 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated  June  29, 
2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a  hack-and-leak 
operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support  of  or  in  response  to 
nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years  of  data  from  200  police 
departments,  fusion  centers,  and  other  law  enforcement  training  and  support  resources  around  the  globe,  according 
to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack-and-leak  activity  against  the  Russian 
Government. 

This  intelligence  information  is  being  passed  through  as  a  courtesy  to  the  originating  agency.  The  STIC  had  no  part  in 
developing  this  information  and  has  not  verified  the  contents  to  be  factual.  If  you  have  any  questions  reference  this 
information  please  contact  the  originating  agency.  Please  ensure  the  Data  Security  designation  on  this  document  is 
adhered  to.  Do  not  advise  individuals  contained  therein  of  this  alert.  Persons  or  organizations  violating  distribution 
restrictions  will  be  prohibited  from  receiving  future  documents  and  will  be  removed  from  distribution  lists.  NO 
REPORT  OR  SEGMENT  THEREOF  MAY  BE  RELEASED  TO  ANY  MEDIA  SOURCES.  Please  contact  STIC  at  877-455-7842  if 
you  have  any  questions  or  need  additional  information. 
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Good  afternoon, 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated  June  29, 
2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a  hack-and-leak 
operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support  of  or  in  response  to 
nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years  of  data  from  200  police 
departments,  fusion  centers,  and  other  law  enforcement  training  and  support  resources  around  the  globe,  according 
to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack-and-leak  activity  against  the  Russian 
Government. 

This  intelligence  information  is  being  passed  through  as  a  courtesy  to  the  originating  agency.  The  STIC  had  no  part  in 
developing  this  information  and  has  not  verified  the  contents  to  be  factual.  If  you  have  any  questions  reference  this 
information  please  contact  the  originating  agency.  Please  ensure  the  Data  Security  designation  on  this  document  is 
adhered  to.  Do  not  advise  individuals  contained  therein  of  this  alert.  Persons  or  organizations  violating  distribution 
restrictions  will  be  prohibited  from  receiving  future  documents  and  will  be  removed  from  distribution  lists.  NO 
REPORT  OR  SEGMENT  THEREOF  MAY  BE  RELEASED  TO  ANY  MEDIA  SOURCES.  Please  contact  STIC  at  877-455-7842  if 
you  have  any  questions  or  need  additional  information. 
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Good  afternoon, 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated  June  29, 
2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a  hack-and-leak 
operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support  of  or  in  response  to 
nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years  of  data  from  200  police 
departments,  fusion  centers,  and  other  law  enforcement  training  and  support  resources  around  the  globe,  according 
to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack-and-leak  activity  against  the  Russian 
Government. 

This  intelligence  information  is  being  passed  through  as  a  courtesy  to  the  originating  agency.  The  STIC  had  no  part  in 
developing  this  information  and  has  not  verified  the  contents  to  be  factual.  If  you  have  any  questions  reference  this 
information  please  contact  the  originating  agency.  Please  ensure  the  Data  Security  designation  on  this  document  is 
adhered  to.  Do  not  advise  individuals  contained  therein  of  this  alert.  Persons  or  organizations  violating  distribution 
restrictions  will  be  prohibited  from  receiving  future  documents  and  will  be  removed  from  distribution  lists.  NO 
REPORT  OR  SEGMENT  THEREOF  MAY  BE  RELEASED  TO  ANY  MEDIA  SOURCES.  Please  contact  STIC  at  877-455-7842  if 
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Good  afternoon, 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated  June  29, 
2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a  hack-and-leak 
operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support  of  or  in  response  to 
nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years  of  data  from  200  police 
departments,  fusion  centers,  and  other  law  enforcement  training  and  support  resources  around  the  globe,  according 
to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack-and-leak  activity  against  the  Russian 
Government. 

This  intelligence  information  is  being  passed  through  as  a  courtesy  to  the  originating  agency.  The  STIC  had  no  part  in 
developing  this  information  and  has  not  verified  the  contents  to  be  factual.  If  you  have  any  questions  reference  this 
information  please  contact  the  originating  agency.  Please  ensure  the  Data  Security  designation  on  this  document  is 
adhered  to.  Do  not  advise  individuals  contained  therein  of  this  alert.  Persons  or  organizations  violating  distribution 
restrictions  will  be  prohibited  from  receiving  future  documents  and  will  be  removed  from  distribution  lists.  NO 
REPORT  OR  SEGMENT  THEREOF  MAY  BE  RELEASED  TO  ANY  MEDIA  SOURCES.  Please  contact  STIC  at  877-455-7842  if 
you  have  any  questions  or  need  additional  information. 
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Good  afternoon, 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated  June  29, 
2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a  hack-and-leak 
operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support  of  or  in  response  to 
nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years  of  data  from  200  police 
departments,  fusion  centers,  and  other  law  enforcement  training  and  support  resources  around  the  globe,  according 
to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack-and-leak  activity  against  the  Russian 
Government. 

This  intelligence  information  is  being  passed  through  as  a  courtesy  to  the  originating  agency.  The  STIC  had  no  part  in 
developing  this  information  and  has  not  verified  the  contents  to  be  factual.  If  you  have  any  questions  reference  this 
information  please  contact  the  originating  agency.  Please  ensure  the  Data  Security  designation  on  this  document  is 
adhered  to.  Do  not  advise  individuals  contained  therein  of  this  alert.  Persons  or  organizations  violating  distribution 
restrictions  will  be  prohibited  from  receiving  future  documents  and  will  be  removed  from  distribution  lists.  NO 
REPORT  OR  SEGMENT  THEREOF  MAY  BE  RELEASED  TO  ANY  MEDIA  SOURCES.  Please  contact  STIC  at  877-455-7842  if 
you  have  any  questions  or  need  additional  information. 
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Good  afternoon, 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated  June  29, 
2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a  hack-and-leak 
operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support  of  or  in  response  to 
nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years  of  data  from  200  police 
departments,  fusion  centers,  and  other  law  enforcement  training  and  support  resources  around  the  globe,  according 
to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack-and-leak  activity  against  the  Russian 
Government. 

This  intelligence  information  is  being  passed  through  as  a  courtesy  to  the  originating  agency.  The  STIC  had  no  part  in 
developing  this  information  and  has  not  verified  the  contents  to  be  factual.  If  you  have  any  questions  reference  this 
information  please  contact  the  originating  agency.  Please  ensure  the  Data  Security  designation  on  this  document  is 
adhered  to.  Do  not  advise  individuals  contained  therein  of  this  alert.  Persons  or  organizations  violating  distribution 
restrictions  will  be  prohibited  from  receiving  future  documents  and  will  be  removed  from  distribution  lists.  NO 
REPORT  OR  SEGMENT  THEREOF  MAY  BE  RELEASED  TO  ANY  MEDIA  SOURCES.  Please  contact  STIC  at  877-455-7842  if 
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Good  afternoon, 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated  June  29, 
2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a  hack-and-leak 
operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support  of  or  in  response  to 
nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years  of  data  from  200  police 
departments,  fusion  centers,  and  other  law  enforcement  training  and  support  resources  around  the  globe,  according 
to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack-and-leak  activity  against  the  Russian 
Government. 

This  intelligence  information  is  being  passed  through  as  a  courtesy  to  the  originating  agency.  The  STIC  had  no  part  in 
developing  this  information  and  has  not  verified  the  contents  to  be  factual.  If  you  have  any  questions  reference  this 
information  please  contact  the  originating  agency.  Please  ensure  the  Data  Security  designation  on  this  document  is 
adhered  to.  Do  not  advise  individuals  contained  therein  of  this  alert.  Persons  or  organizations  violating  distribution 
restrictions  will  be  prohibited  from  receiving  future  documents  and  will  be  removed  from  distribution  lists.  NO 
REPORT  OR  SEGMENT  THEREOF  MAY  BE  RELEASED  TO  ANY  MEDIA  SOURCES.  Please  contact  STIC  at  877-455-7842  if 
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Good  afternoon, 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated  June  29, 
2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a  hack-and-leak 
operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support  of  or  in  response  to 
nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years  of  data  from  200  police 
departments,  fusion  centers,  and  other  law  enforcement  training  and  support  resources  around  the  globe,  according 
to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack-and-leak  activity  against  the  Russian 
Government. 

This  intelligence  information  is  being  passed  through  as  a  courtesy  to  the  originating  agency.  The  STIC  had  no  part  in 
developing  this  information  and  has  not  verified  the  contents  to  be  factual.  If  you  have  any  questions  reference  this 
information  please  contact  the  originating  agency.  Please  ensure  the  Data  Security  designation  on  this  document  is 
adhered  to.  Do  not  advise  individuals  contained  therein  of  this  alert.  Persons  or  organizations  violating  distribution 
restrictions  will  be  prohibited  from  receiving  future  documents  and  will  be  removed  from  distribution  lists.  NO 
REPORT  OR  SEGMENT  THEREOF  MAY  BE  RELEASED  TO  ANY  MEDIA  SOURCES.  Please  contact  STIC  at  877-455-7842  if 
you  have  any  questions  or  need  additional  information. 
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Good  afternoon, 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated  June  29, 
2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a  hack-and-leak 
operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support  of  or  in  response  to 
nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years  of  data  from  200  police 
departments,  fusion  centers,  and  other  law  enforcement  training  and  support  resources  around  the  globe,  according 
to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack-and-leak  activity  against  the  Russian 
Government. 

This  intelligence  information  is  being  passed  through  as  a  courtesy  to  the  originating  agency.  The  STIC  had  no  part  in 
developing  this  information  and  has  not  verified  the  contents  to  be  factual.  If  you  have  any  questions  reference  this 
information  please  contact  the  originating  agency.  Please  ensure  the  Data  Security  designation  on  this  document  is 
adhered  to.  Do  not  advise  individuals  contained  therein  of  this  alert.  Persons  or  organizations  violating  distribution 
restrictions  will  be  prohibited  from  receiving  future  documents  and  will  be  removed  from  distribution  lists.  NO 
REPORT  OR  SEGMENT  THEREOF  MAY  BE  RELEASED  TO  ANY  MEDIA  SOURCES.  Please  contact  STIC  at  877-455-7842  if 
you  have  any  questions  or  need  additional  information. 


(U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 
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To: 

Sent: 

Received: 

Attachments: 


ISP.DoNotReply  <ISP.DoNotReply@lllinois.gov> 

Craig  A  Wilk  #747  <craig.wilk@cookcountyil.gov>,  Craig  Wilk  (Sheriff) 
<Craig.Wilk@cookcountyil.gov> 

June  29,  2020  3:12:35  PM  CDT 
June  29,  2020  3:15:48  PM  CDT 

(U--FOUO)  I  IB  -  Criminal  Flackers  Target  US  Law  Enforcement  Data 
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External  Message  Disclaimer 


j  This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when  j 
opening  attachments,  clicking  links,  or  responding  to  this  email. 

The  following  information  is  being  disseminated  by  STIC  to  our  email  distribution  list  for  situational 

awareness  purposes.  Replies  can  be  sent  to  stic@illinois.gov. 

Good  afternoon, 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated  June  29, 
2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a  hack-and-leak 
operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support  of  or  in  response  to 
nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years  of  data  from  200  police 
departments,  fusion  centers,  and  other  law  enforcement  training  and  support  resources  around  the  globe,  according 
to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack-and-leak  activity  against  the  Russian 
Government. 

This  intelligence  information  is  being  passed  through  as  a  courtesy  to  the  originating  agency.  The  STIC  had  no  part  in 
developing  this  information  and  has  not  verified  the  contents  to  be  factual.  If  you  have  any  questions  reference  this 
information  please  contact  the  originating  agency.  Please  ensure  the  Data  Security  designation  on  this  document  is 
adhered  to.  Do  not  advise  individuals  contained  therein  of  this  alert.  Persons  or  organizations  violating  distribution 
restrictions  will  be  prohibited  from  receiving  future  documents  and  will  be  removed  from  distribution  lists.  NO 
REPORT  OR  SEGMENT  THEREOF  MAY  BE  RELEASED  TO  ANY  MEDIA  SOURCES.  Please  contact  STIC  at  877-455-7842  if 
you  have  any  questions  or  need  additional  information. 


(U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 


From: 

To: 

Sent: 

Received: 

Attachments: 


ISP.DoNotReply  <ISP.DoNotReply@lllinois.gov> 

Richard  Brogan  <Richard.brogan@cookcountyil.gov>,  Richard  Brogan 
(Sheriff)  <Richard.Brogan@cookcountyil.gov> 

June  29,  2020  3:12:35  PM  CDT 
June  29,  2020  3:16:32  PM  CDT 

(U--FOUO)  I  IB  -  Criminal  Flackers  Target  US  Law  Enforcement  Data 
06262020.pdf 


External  Message  Disclaimer 


j  This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when  j 
opening  attachments,  clicking  links,  or  responding  to  this  email. 

The  following  information  is  being  disseminated  by  STIC  to  our  email  distribution  list  for  situational 

awareness  purposes.  Replies  can  be  sent  to  stic@illinois.gov. 

Good  afternoon, 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated  June  29, 
2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a  hack-and-leak 
operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support  of  or  in  response  to 
nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years  of  data  from  200  police 
departments,  fusion  centers,  and  other  law  enforcement  training  and  support  resources  around  the  globe,  according 
to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack-and-leak  activity  against  the  Russian 
Government. 

This  intelligence  information  is  being  passed  through  as  a  courtesy  to  the  originating  agency.  The  STIC  had  no  part  in 
developing  this  information  and  has  not  verified  the  contents  to  be  factual.  If  you  have  any  questions  reference  this 
information  please  contact  the  originating  agency.  Please  ensure  the  Data  Security  designation  on  this  document  is 
adhered  to.  Do  not  advise  individuals  contained  therein  of  this  alert.  Persons  or  organizations  violating  distribution 
restrictions  will  be  prohibited  from  receiving  future  documents  and  will  be  removed  from  distribution  lists.  NO 
REPORT  OR  SEGMENT  THEREOF  MAY  BE  RELEASED  TO  ANY  MEDIA  SOURCES.  Please  contact  STIC  at  877-455-7842  if 
you  have  any  questions  or  need  additional  information. 


(U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 


From: 

To: 

Sent: 

Received: 

Attachments: 


ISP.DoNotReply  <ISP.DoNotReply@lllinois.gov> 
patrick.doyle@cookcountyil.gov,  Patrick  Doyle  (Sheriff) 
<Patrick.Doyle@cookcountyil.gov> 

June  29,  2020  3:12:35  PM  CDT 
June  29,  2020  3:16:44  PM  CDT 

(U--FOUO)  I  IB  -  Criminal  Flackers  Target  US  Law  Enforcement  Data 
06262020.pdf 


External  Message  Disclaimer 


j  This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when  j 
opening  attachments,  clicking  links,  or  responding  to  this  email. 

The  following  information  is  being  disseminated  by  STIC  to  our  email  distribution  list  for  situational 

awareness  purposes.  Replies  can  be  sent  to  stic@illinois.gov. 

Good  afternoon, 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated  June  29, 
2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a  hack-and-leak 
operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support  of  or  in  response  to 
nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years  of  data  from  200  police 
departments,  fusion  centers,  and  other  law  enforcement  training  and  support  resources  around  the  globe,  according 
to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack-and-leak  activity  against  the  Russian 
Government. 

This  intelligence  information  is  being  passed  through  as  a  courtesy  to  the  originating  agency.  The  STIC  had  no  part  in 
developing  this  information  and  has  not  verified  the  contents  to  be  factual.  If  you  have  any  questions  reference  this 
information  please  contact  the  originating  agency.  Please  ensure  the  Data  Security  designation  on  this  document  is 
adhered  to.  Do  not  advise  individuals  contained  therein  of  this  alert.  Persons  or  organizations  violating  distribution 
restrictions  will  be  prohibited  from  receiving  future  documents  and  will  be  removed  from  distribution  lists.  NO 
REPORT  OR  SEGMENT  THEREOF  MAY  BE  RELEASED  TO  ANY  MEDIA  SOURCES.  Please  contact  STIC  at  877-455-7842  if 
you  have  any  questions  or  need  additional  information. 


(U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 


From: 

To: 

Sent: 

Received: 

Attachments: 


ISP.DoNotReply  <ISP.DoNotReply@lllinois.gov> 

Tarry  Williams  <Tarry.williams@cookcountyil.gov>,  Tarry  Williams  (Sheriff) 
<Tarry.Williams@cookcountyil.gov> 

June  29,  2020  3:12:35  PM  CDT 
June  29,  2020  3:17:10  PM  CDT 

(U--FOUO)  I  IB  -  Criminal  Flackers  Target  US  Law  Enforcement  Data 
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External  Message  Disclaimer 


j  This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when  j 
opening  attachments,  clicking  links,  or  responding  to  this  email. 

The  following  information  is  being  disseminated  by  STIC  to  our  email  distribution  list  for  situational 

awareness  purposes.  Replies  can  be  sent  to  stic@illinois.gov. 

Good  afternoon, 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated  June  29, 
2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a  hack-and-leak 
operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support  of  or  in  response  to 
nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years  of  data  from  200  police 
departments,  fusion  centers,  and  other  law  enforcement  training  and  support  resources  around  the  globe,  according 
to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack-and-leak  activity  against  the  Russian 
Government. 

This  intelligence  information  is  being  passed  through  as  a  courtesy  to  the  originating  agency.  The  STIC  had  no  part  in 
developing  this  information  and  has  not  verified  the  contents  to  be  factual.  If  you  have  any  questions  reference  this 
information  please  contact  the  originating  agency.  Please  ensure  the  Data  Security  designation  on  this  document  is 
adhered  to.  Do  not  advise  individuals  contained  therein  of  this  alert.  Persons  or  organizations  violating  distribution 
restrictions  will  be  prohibited  from  receiving  future  documents  and  will  be  removed  from  distribution  lists.  NO 
REPORT  OR  SEGMENT  THEREOF  MAY  BE  RELEASED  TO  ANY  MEDIA  SOURCES.  Please  contact  STIC  at  877-455-7842  if 
you  have  any  questions  or  need  additional  information. 


(U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

From:  ISP.DoNotReply  <ISP.DoNotReply@lllinois.gov> 

To:  John  Konrad  <john.konrad@cookcountyil.gov>,  John  Konrad  (Sheriff) 

<John.Konrad@cookcountyil.gov> 

Sent:  June  29,  2020  3:12:35  PM  CDT 

Received:  June  29,  2020  3:16:1 1  PM  CDT 

Attachments:  (U--FOUO)  I  IB  -  Criminal  Flackers  Target  US  Law  Enforcement  Data 
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External  Message  Disclaimer 


j  This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when  j 
opening  attachments,  clicking  links,  or  responding  to  this  email. 

The  following  information  is  being  disseminated  by  STIC  to  our  email  distribution  list  for  situational 

awareness  purposes.  Replies  can  be  sent  to  stic@illinois.gov. 

Good  afternoon, 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated  June  29, 
2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a  hack-and-leak 
operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support  of  or  in  response  to 
nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years  of  data  from  200  police 
departments,  fusion  centers,  and  other  law  enforcement  training  and  support  resources  around  the  globe,  according 
to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack-and-leak  activity  against  the  Russian 
Government. 

This  intelligence  information  is  being  passed  through  as  a  courtesy  to  the  originating  agency.  The  STIC  had  no  part  in 
developing  this  information  and  has  not  verified  the  contents  to  be  factual.  If  you  have  any  questions  reference  this 
information  please  contact  the  originating  agency.  Please  ensure  the  Data  Security  designation  on  this  document  is 
adhered  to.  Do  not  advise  individuals  contained  therein  of  this  alert.  Persons  or  organizations  violating  distribution 
restrictions  will  be  prohibited  from  receiving  future  documents  and  will  be  removed  from  distribution  lists.  NO 
REPORT  OR  SEGMENT  THEREOF  MAY  BE  RELEASED  TO  ANY  MEDIA  SOURCES.  Please  contact  STIC  at  877-455-7842  if 
you  have  any  questions  or  need  additional  information. 


(U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 
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To: 

Sent: 

Received: 

Attachments: 


ISP.DoNotReply  <ISP.DoNotReply@lllinois.gov> 

Jerome  Ryan  <jerome.ryan@cookcountyil.gov>,  Jerome  Ryan  (Sheriff) 
<Jerome.Ryan@cookcountyil.gov> 

June  29,  2020  3:12:35  PM  CDT 
June  29,  2020  3:16:17  PM  CDT 
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External  Message  Disclaimer 


j  This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when  j 
opening  attachments,  clicking  links,  or  responding  to  this  email. 

The  following  information  is  being  disseminated  by  STIC  to  our  email  distribution  list  for  situational 

awareness  purposes.  Replies  can  be  sent  to  stic@illinois.gov. 

Good  afternoon, 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated  June  29, 
2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a  hack-and-leak 
operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support  of  or  in  response  to 
nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years  of  data  from  200  police 
departments,  fusion  centers,  and  other  law  enforcement  training  and  support  resources  around  the  globe,  according 
to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack-and-leak  activity  against  the  Russian 
Government. 

This  intelligence  information  is  being  passed  through  as  a  courtesy  to  the  originating  agency.  The  STIC  had  no  part  in 
developing  this  information  and  has  not  verified  the  contents  to  be  factual.  If  you  have  any  questions  reference  this 
information  please  contact  the  originating  agency.  Please  ensure  the  Data  Security  designation  on  this  document  is 
adhered  to.  Do  not  advise  individuals  contained  therein  of  this  alert.  Persons  or  organizations  violating  distribution 
restrictions  will  be  prohibited  from  receiving  future  documents  and  will  be  removed  from  distribution  lists.  NO 
REPORT  OR  SEGMENT  THEREOF  MAY  BE  RELEASED  TO  ANY  MEDIA  SOURCES.  Please  contact  STIC  at  877-455-7842  if 
you  have  any  questions  or  need  additional  information. 


(U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 


From: 

To: 

Sent: 

Received: 

Attachments: 


ISP.DoNotReply  <ISP.DoNotReply@lllinois.gov> 
peter.pon@cookcountyil.gov,  Peter  Pon  (Sheriff) 
<Peter.Pon@cookcountyil.gov> 

June  29,  2020  3:12:35  PM  CDT 
June  29,  2020  3:16:55  PM  CDT 

(U--FOUO)  I  IB  -  Criminal  Flackers  Target  US  Law  Enforcement  Data 
06262020.pdf 


External  Message  Disclaimer 


j  This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when  j 
opening  attachments,  clicking  links,  or  responding  to  this  email. 

The  following  information  is  being  disseminated  by  STIC  to  our  email  distribution  list  for  situational 

awareness  purposes.  Replies  can  be  sent  to  stic@illinois.gov. 

Good  afternoon, 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated  June  29, 
2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a  hack-and-leak 
operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support  of  or  in  response  to 
nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years  of  data  from  200  police 
departments,  fusion  centers,  and  other  law  enforcement  training  and  support  resources  around  the  globe,  according 
to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack-and-leak  activity  against  the  Russian 
Government. 

This  intelligence  information  is  being  passed  through  as  a  courtesy  to  the  originating  agency.  The  STIC  had  no  part  in 
developing  this  information  and  has  not  verified  the  contents  to  be  factual.  If  you  have  any  questions  reference  this 
information  please  contact  the  originating  agency.  Please  ensure  the  Data  Security  designation  on  this  document  is 
adhered  to.  Do  not  advise  individuals  contained  therein  of  this  alert.  Persons  or  organizations  violating  distribution 
restrictions  will  be  prohibited  from  receiving  future  documents  and  will  be  removed  from  distribution  lists.  NO 
REPORT  OR  SEGMENT  THEREOF  MAY  BE  RELEASED  TO  ANY  MEDIA  SOURCES.  Please  contact  STIC  at  877-455-7842  if 
you  have  any  questions  or  need  additional  information. 


(U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Patrick  Moriarty  (Sheriff) 

Sent:  June  29,  2020  3:12:35  PM  CDT 

Received:  June  29,  2020  3:1 7:1 8  PM  CDT 


(U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Phillip  Mackey  (Sheriff) 

Sent:  June  29,  2020  3:12:35  PM  CDT 

Received:  June  29,  2020  3:1 6:1 8  PM  CDT 


(U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Theodore  Stajura  (Sheriff) 

Sent:  June  29,  2020  3:12:35  PM  CDT 

Received:  June  29,  2020  3:1 7:06  PM  CDT 


(U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Craig  Wilk  (Sheriff) 

Sent:  June  29,  2020  3:12:35  PM  CDT 

Received:  June  29,  2020  3:1 5:48  PM  CDT 


FW:  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Sheriff  Intel 

Sent:  June  29,  2020  3:1 9:50  PM  CDT 

Received:  June  29,  2020  3:1 9:53  PM  CDT 


FW:  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 


From: 

To: 

Sent: 

Received: 

Attachments: 


Kathleen  Urbanczyk  (Sheriff)  <Kathleen. Urbanczyk@cookcountyil.gov> 
Kathryn  Schwendener  (Sheriff)  <Kathryn. Schwendener@cookcountyil.gov> 
June  29,  2020  3:25:50  PM  CDT 
June  29,  2020  3:25:51  PM  CDT 

(U--FOUO)  I  IB  -  Criminal  Flackers  Target  US  Law  Enforcement  Data 
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From:  CCSO  Intel  (Sheriff)  <CCSO.INTEL@cookcountyiLgov> 

Sent:  Monday,  June  29,  2020  3:20  PM 

To:  Sheriff  Intel  <sheriff.intel@cookcountyil.gov> 

Subject:  FW:  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 


From:  ISP.DoNotReply 

Sent:  Monday,  June  29,  2020  3:12:35  PM  (UTC-06:00)  Central  Time  (US  &  Canada) 
To:  CCSO  Intel  (Sheriff) 

Subject:  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 


External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 


The  following  information  is  being  disseminated  by  STIC  to  our  email  distribution  list  for  situational  awareness 

purposes.  Replies  can  be  sent  to  stic@illinois.gov. 

Good  afternoon, 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated  June  29, 
2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a  hack-and-leak 
operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support  of  or  in  response  to 
nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years  of  data  from  200  police 
departments,  fusion  centers,  and  other  law  enforcement  training  and  support  resources  around  the  globe,  according 
to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack-and-leak  activity  against  the  Russian 
Government. 

This  intelligence  information  is  being  passed  through  as  a  courtesy  to  the  originating  agency.  The  STIC  had  no  part  in 
developing  this  information  and  has  not  verified  the  contents  to  be  factual.  If  you  have  any  questions  reference  this 
information  please  contact  the  originating  agency.  Please  ensure  the  Data  Security  designation  on  this  document  is 
adhered  to.  Do  not  advise  individuals  contained  therein  of  this  alert.  Persons  or  organizations  violating  distribution 
restrictions  will  be  prohibited  from  receiving  future  documents  and  will  be  removed  from  distribution  lists.  NO 
REPORT  OR  SEGMENT  THEREOF  MAY  BE  RELEASED  TO  ANY  MEDIA  SOURCES.  Please  contact  STIC  at  877-455-7842  if 
you  have  any  questions  or  need  additional  information. 


FW:  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 


From: 


To: 

Sent: 

Received: 

Attachments: 


Kathleen  Urbanczyk  (Sheriff)  </0=EXCHANGELABS/OU=EXCHANGE 
ADMINISTRATIVE  GROUP 

(FYDIBOHF23SPDLT)/CN=RECIPIENTS/CN=AAE0F208D8C54334A96AA19F2B1E404 
8-KATHLEEN  UR> 

Kathryn  Schwendener  (Sheriff)  <Kathryn. Schwendener@cookcountyil.gov> 

June  29,  2020  3:25:50  PM  CDT 
June  29,  2020  3:25:00  PM  CDT 

(U--FOUO)  MB  -  Criminal  Flackers  Target  US  Law  Enforcement  Data  06262020.pdf 


From:  CCSO  Intel  (Sheriff)  <CCSO.INTEL@cookcountyil.gov> 

Sent:  Monday,  June  29,  2020  3:20  PM 

To:  Sheriff  Intel  <sheriff.intel@cookcountyil.gov> 

Subject:  FW:  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 


From:  ISP.DoNotReply 

Sent:  Monday,  June  29,  2020  3:12:35  PM  (UTC-06:00)  Central  Time  (US  &  Canada) 
To:  CCSO  Intel  (Sheriff) 

Subject:  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 


External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 


The  following  information  is  being  disseminated  by  STIC  to  our  email  distribution  list  for  situational  awareness 

purposes.  Replies  can  be  sent  to  stic@illinois.gov. 

Good  afternoon, 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated  June  29, 
2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a  hack-and-leak 
operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support  of  or  in  response  to 
nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years  of  data  from  200  police 
departments,  fusion  centers,  and  other  law  enforcement  training  and  support  resources  around  the  globe,  according 
to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack-and-leak  activity  against  the  Russian 
Government. 

This  intelligence  information  is  being  passed  through  as  a  courtesy  to  the  originating  agency.  The  STIC  had  no  part  in 
developing  this  information  and  has  not  verified  the  contents  to  be  factual.  If  you  have  any  questions  reference  this 
information  please  contact  the  originating  agency.  Please  ensure  the  Data  Security  designation  on  this  document  is 
adhered  to.  Do  not  advise  individuals  contained  therein  of  this  alert.  Persons  or  organizations  violating  distribution 
restrictions  will  be  prohibited  from  receiving  future  documents  and  will  be  removed  from  distribution  lists.  NO 
REPORT  OR  SEGMENT  THEREOF  MAY  BE  RELEASED  TO  ANY  MEDIA  SOURCES.  Please  contact  STIC  at  877-455-7842  if 
you  have  any  questions  or  need  additional  information. 


FW:  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 


To:  Kathryn  Schwendener  (Sheriff) 

Sent:  June  29,  2020  3:25:50  PM  CDT 

Received:  June  29,  2020  3:25:00  PM  CDT 


Good  Cyber  Hygiene  in  a  Post  COVID  World  |  Average  Cost  of  a  Data  Breach: 
$1 1 6M  |  5  Steps  for  Implementing  Multicloud  Identity 

From:  Information  Management  Today  Weekly  <editors@aggregage.com> 

To:  Keith  Morrison  <keith.morrison@cookcountyil.gov>,  Keith  Morrison  (Sheriff) 

<Keith.Morrison@cookcountyil.gov> 

Sent:  June  29,  2020  9:28:49  PM  CDT 

Received:  June  29,  2020  9:28:58  PM  CDT 


External  Message  Disclaimer 

|  This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 

Top  articles  on  Security  and  Government.  Edition: 

Week 
of  Jun 
20, 

2020 

■  Information  Management  Today  Brought  to  you  by 

Expert  insights.  Personalized  for  you. 


Trending  Articles: 


Pressure  Points:  How  to  Ensure  Your  B2B 
Pipeline  Passes  Inspection 

This  eBook  highlights  best  practices  for  developing  a  pipeline 
management  process  that  helps  sales  leaders  and  their  team 
C.L.O.S.E  (you’ll  see  what  we  mean  in  this  eBook)  more  revenue 
through  data-driven  prospecting,  stage  analysis,  and  subsequent 
sales  enablement. 


ADVERTISER:  ZOOMINFO 


Future-Proofing  Your  Information 
Governance  Strategy 

Join  Onna  and  experts  from  Quip,  Airbnb,  and  Oracle  for  this 
recorded  webinar  as  they  dive  into  proactive  data  deletion  policies, 
retention  strategies,  and  legal  hold  practices  that  are  essential  to  a 
modern  enterprise  information  governance  strategy. 

ADVERTISER:  ONNA 


Good  Cyber  Hygiene  in  a  Post-Pandemic 
World  Starts  with  Us 

Three  ways  that  security  teams  can  improve  processes  and 
collaboration,  all  while  creating  the  common  ground  needed  to 
sustain  them 
DARK  READING 


Average  Cost  of  a  Data  Breach:  $11 6M 

Sensitivity  of  customer  information  and  time-to-detection  determine 
financial  blowback  of  cybersecurity  breaches 
DARK  READING 


5  Steps  for  Implementing  Multicloud  Identity 

Why  embracing,  not  fighting,  decentralization  will  pave  the  way  to 
smoother  cloud  migrations 
DARK  READING 


Check  out  the  full  edition! 


Picked  For  You 


US  Now  Accuses  Assange  of  Conspiring 
With  Hacking  Groups 

Superseding  Indictment  Expands  Scope  of  Case,  But  Doesn't  Add 
Charges  The  U.S  Department  of  Justice  unsealed  a  superseding 
indictment  against  WikiLeaks  founder  Julian  Assange  that  expands 
the  scope  of  the  government's  case  against  him. 

DATA  BREACH  TODAY 


‘BlueLeaks’  Exposes  Files  from  Hundreds  of 
Police  Departments 

Hundreds  of  thousands  of  potentially  sensitive  files  from  police 
departments  across  the  United  States  were  leaked  online  last  week. 
The  collection,  dubbed  “  BlueLeaks  ”  and  made  searchable  online, 
stems  from  a  security  breach  at  a  Texas  web  design  and  hosting 
company  that  maintains  a  number  of  state  law  enforcement  data- 
sharing  portals. 

KREBS  ON  SECURITY 


MY  TAKE:  Remote  classes,  mobile 
computing  heighten  need  for  a  security 
culture  in  K-12  schools 

Parents  have  long  held  a  special  duty  to  protect  their  school-aged 
children  from  bad  actors  on  the  Internet.  Related:  Mock  attacks  help 
schools  defend  themselves  Now  COVID-19  has  dramatically  and 
permanently  expanded  that  parental  responsibility,  as  well  as 
extended  it  to  ill-prepared  school  officials  in  K-12  campuses  all  across 
the  nation. 

THE  LAST  WATCHDOG 


More  Trending 


Anonymous  Stole  and  Leaked  a  Megatrove  of 
Police  Documents 

The  so-called  BlueLeaks  collection  includes  internal  memos,  financial 
records,  and  more  from  over  200  state,  local,  and  federal  agencies. 
Security  Security  /  Cyberattacks  and  Hacks 
WIRED  THREAT  LEVEL 


Nephilim  Ransomware  Gang  Tied  to  Citrix 
Gateway  Hacks 

DATA  BREACH  TODAY 


New  Charges,  Sentencing  in  Satori  loT 
Botnet  Conspiracy 

The  U.S.  Justice  Department  today  criminally  charged  a  Canadian 
and  a  Northern  Ireland  man  for  allegedly  conspiring  to  build  botnets 
that  enslaved  hundreds  of  thousands  of  routers  and  other  Internet  of 
Things  (loT)  devices  for  use  in  large-scale  distributed  denial-of- 
service  (DDoS)  attacks. 

KREBS  ON  SECURITY 


Click  here  to  see  this  edition  in  full,  including: 

SHARED  INTEL:  How  ransomware  evolved  from  consumer  trickery  to  deep 
enterprise  hacks 

THE  LAST  WATCHDOG 

Developer  of  DDoS  Mirai  based  botnets  sentenced  to  prison 

PIERLUIGI  PAGANINI 

Breach  Notification  Delay:  A  Step-by-Step  Timeline 

DATA  BREACH  TODAY 

5  New  InfoSec  Job  Training  Trends:  What  We're  Studying  During  COVID-19 

DARK  READING 


COVID-19  Risks  of  Flying 

SCHNEIER  ON  SECURITY 

Akamai  mitigated  the  largest  ever  PPS  DDoS  attack 

SECURITY  AFFAIRS 

Payment  Card  Skimmer  Attacks  Hit  8  Cities 

An  Embattled  Group  of  Leakers  Picks  Up  the  WikiLeaks  Mantle 

WIRED  THREAT  LEVEL 

Cybercrime  Infrastructure  Never  Really  Dies 

DARK  READING 

Moroccan  journalist  targeted  with  network  injection  attacks  using  NSO  Group  ‘s 
spyware 

SECURITY  AFFAIRS 


Check  out  the  full  edition! 
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to  keith.morrison@cookcountyil.gov.  To  stop  receiving  emails  at  this  address  manage  vour  subscription  or  unsubscribe. 
Powered  by  Aggregage  -  expert  insights,  personalized  for  you..  Forward  this  email  to  a  friend! 


[GovQA]  FOIA  Request  -  New  Assignment  -  R009142-062920 

From:  Cook  County  Sheriff's  Office  <cookcountysheriff@govqa.us> 

To:  Elizabeth.Scannell@cookcountyil.gov,  Elizabeth  Scannell  (Sheriff) 

<Eliza  beth.Scannell@cookcountyil.gov> 

Sent:  June  30,  2020  7:56:10  AM  CDT 

Received:  June  30,  2020  7:56:13  AM  CDT 


External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 


A  request  has  been  assigned  to  you:  FOIA  Request  /  R009142-062920 

FOIA  Request  for  Records 
Assigned  Staff:  Elizabeth  Scannell 
Status:  Received 
Create  Date:  June  29,  2020 
Due  Date:  July  06,  2020 
Name  of  Requester:  Emma  Best 
Requester  Affiliation:  Press 

Record(s)  Requested:  To  Whom  It  May  Concern:  Pursuant  to  the  Illinois  Freedom  of  Information  Act., 
I  hereby  request  the  following  records:  1.  Documents  mentioning,  describing  or  generated  in  response  to 
the  BlueLeaks  release,  the  preceding  hack  or  subsequent  fallout,  including  but  not  limited  to:  *  Damage 
assessments  *  Emails  *  Interagency  communications  (local,  state,  or  federal)  *  Communications  with 
the  press  about  BlueLeaks  *  Communications  with  Twitter  or  other  social  media  or  sharing  platforms  2. 
Documents  mentioning  or  describing  Distributed  Denial  of  Secrets  (DDoSecrets)  You  may  limit  this 
request  to  records  generated  between  November  1,  2018  and  the  present.  I  am  a  member  of  the  news 
media  and  request  classification  as  such.  I  have  previously  written  about  the  government  and  its 
activities,  with  some  reaching  over  100,000  readers  in  outlets  such  as  Gizmodo,  MuckRock, 
Motherboard,  Property  of  the  People,  Unicorn  Riot,  and  The  Outline,  among  others.  As  such,  as  I  have  a 
reasonable  expectation  of  publication  and  my  editorial  and  writing  skills  are  well  established.  In 
addition,  I  discuss  and  comment  on  the  files  online  and  make  them  available  through  non-profits  such  as 
the  library  Internet  Archive  and  the  journalist  non-profit  MuckRock,  disseminating  them  to  a  large 
audience.  While  my  research  is  not  limited  to  this,  a  great  deal  of  it,  including  this,  focuses  on  the 
activities  and  attitudes  of  the  government  itself.  As  such,  it  is  not  necessary  for  me  to  demonstrate  the 
relevance  of  this  particular  subject  in  advance.  As  my  primary  purpose  is  to  inform  about  government 
activities  by  reporting  on  it  and  making  the  raw  data  available,  I  request  that  fees  be  waived.  The 
requested  documents  will  be  made  available  to  the  general  public,  and  this  request  is  not  being  made  for 
commercial  purposes.  In  the  event  that  there  are  fees,  I  would  be  grateful  if  you  would  inform  me  of  the 
total  charges  in  advance  of  fulfilling  my  request.  I  would  prefer  the  request  filled  electronically,  by  e- 
mail  attachment  if  available  or  CD-ROM  if  not.  Thank  you  in  advance  for  your  anticipated  cooperation 
in  this  matter.  I  look  forward  to  receiving  your  response  to  this  request  within  5  business  days,  as  the 
statute  requires.  Sincerely,  Emma  Best  Upload  documents  directly: 

https://https://www.muckrock.comhttps://accounts.muckrock.com/accounts/login/?next=https%3A%2F 

%2Fwww.muckrockcom%2Faccounts%2Flogin%2F%3Fnext%3D%252Faccounts%252Fagency_login 

%252Fcook-county-sheriff-719%252Fblueleaks-cook-county-sheriff- 

9694 1  %252F%253F&url_auth_token=AAAaaJnszUVssmdgx6fh2R- 

tE3U%3AljppAE%3ADWZbgy7n8640ATjAMxtAsPZltYs 


Login  to  the  system  and  view  your  request  by  clicking  HERE.  Your  username  and  password  is  the  same 
as  your  Active  Directory  login,  used  to  access  all  CCSO  computers.  If  you  have  any  questions  or 
concerns  regarding  this  email  notification,  please  contact  the  Legal  Department  at  312-603-6444. 


This  is  an  auto-generated  email  and  has  originated  from  an  unmonitored  email  account.  Please  DO  NOT  REPLY  to 
this  email  as  the  contents  of  your  response  and  any  attachments  may  be  externally  disseminated  inadvertently.  Click 
the  link  above  to  respond  and  upload  documents  for  secure  internal  review. 


Emma  Best  FOIA  R009142-062920 


From:  Eryn  Hedderman  (Sheriff)  <Eryn. Hedderman@cookcountyil.gov> 

To:  Elizabeth  Scannell  (Sheriff)  <Elizabeth.Scannell@cookcountyil.gov> 

Sent:  June  30,  2020  7:58:48  AM  CDT 

Received:  June  30,  2020  7:58:49  AM  CDT 

Attachments:  FOIA  R009142-062920.pdf 

Hello! 

We  received  the  attached  FOIA  request  from  Emma  Best,  including  emails.  I  have  assigned  this  for  you  on  GovQA. 
Thank  you, 

Eryn  Hedderman 

Cook  County  Sheriff's  Office 
FOIA  Support/Legal  Department 

The  contents  of  this  e-mail  message  and  any  attachments  are  intended  solely  for  the  addressee(s)  named  in  this  message.  This  communication 
is  intended  to  be  and  to  remain  confidential  and  may  be  subject  to  applicable  attorney-client  and/or  work  product  privileges.  If  you  are  not  the 
intended  recipient  of  this  message  or  if  this  message  has  been  addressed  to  you  in  error,  please  alert  the  sender  immediately  by  reply  e-mail 
and  then  delete  this  message  and  its  attachments.  Do  not  deliver,  distribute  or  copy  this  message  and/or  any  attachments  and  if  you  are  not 
the  intended  recipient,  do  not  disclose  the  contents  or  take  any  action  in  reliance  upon  the  information  contained  in  this  communication  or 
any  attachments.  Thank  you. 


Emma  Best  FOIA  R009142-062920 


From: 


To: 

Sent: 

Received: 

Attachments: 

Hello! 


Eryn  Hedderman  (Sheriff)  </0=EXCHANGELABS/OU=EXCHANGE  ADMINISTRATIVE 
GROUP 

(FYDIBOHF23SPDLT)/CN=RECIPIENTS/CN=DA84F6C14E4A40FFB4B4B24D87E04CEF 
-ERYN  T.  HED> 

Elizabeth  Scannell  (Sheriff)  <Elizabeth.Scannell@cookcountyil.gov> 

June  30,  2020  7:58:48  AM  CDT 
June  30,  2020  7:58:00  AM  CDT 
FOIA  R009142-062920.pdf 


We  received  the  attached  FOIA  request  from  Emma  Best,  including  emails.  I  have  assigned  this  for  you  on  GovQA. 
Thank  you, 

Eryn  Hedderman 

Cook  County  Sheriff's  Office 
FOIA  Support/Legal  Department 


The  contents  of  this  e-mail  message  and  any  attachments  are  intended  solely  for  the  addressee(s)  named  in  this  message.  This  communication 
is  intended  to  be  and  to  remain  confidential  and  may  be  subject  to  applicable  attorney-client  and/or  work  product  privileges.  If  you  are  not  the 
intended  recipient  of  this  message  or  if  this  message  has  been  addressed  to  you  in  error,  please  alert  the  sender  immediately  by  reply  e-mail 
and  then  delete  this  message  and  its  attachments.  Do  not  deliver,  distribute  or  copy  this  message  and/or  any  attachments  and  if  you  are  not 
the  intended  recipient,  do  not  disclose  the  contents  or  take  any  action  in  reliance  upon  the  information  contained  in  this  communication  or 
any  attachments.  Thank  you. 


Emma  Best  FOIA  R0091 42-062920 


To: 

Sent: 

Received: 


Elizabeth  Scannell  (Sheriff) 
June  30,  2020  7:58:48  AM  CDT 
June  30,  2020  7:58:00  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

Sent:  June  30,  2020  8:06:39  AM  CDT 

Received:  June  30,  2020  8:06:47  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Sheriff  Intel 

Sent:  June  30,  2020  8:06:39  AM  CDT 

Received:  June  30,  2020  8:06:48  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Sheriff  Intel,  Paul  Villanueva  (Sheriff) 

Sent:  June  30,  2020  8:06:39  AM  CDT 

Received:  June  30,  2020  8:06:47  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Michael  Rowe  (Sheriff) 

Sent:  June  30,  2020  8:06:39  AM  CDT 

Received:  June  30,  2020  8:06:48  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  George  Winistorfer  (Sheriff) 

Sent:  June  30,  2020  8:06:39  AM  CDT 

Received:  June  30,  2020  8:06:48  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Anastasios  Goulos  (Sheriff) 

Sent:  June  30,  2020  8:06:39  AM  CDT 

Received:  June  30,  2020  8:06:47  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Ricky  Soto  (Sheriff) 

Sent:  June  30,  2020  8:06:39  AM  CDT 

Received:  June  30,  2020  8:06:47  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Nicole  Pagani  (Sheriff) 

Sent:  June  30,  2020  8:06:39  AM  CDT 

Received:  June  30,  2020  8:06:48  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Darren  Ganir  (Sheriff) 

Sent:  June  30,  2020  8:06:39  AM  CDT 

Received:  June  30,  2020  8:06:47  AM  CDT 


Pass  Through  - 

To: 

Cc: 

Sent: 

Received: 


[U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 


Amar  Patel  (Sheriff),  Keith  Morrison  (Sheriff),  Adnan  Memon  (Sheriff),  Douglas 
Maclean  (Sheriff) 

Adnan  Memon  (Sheriff),  Douglas  Maclean  (Sheriff),  Amar  Patel  (Sheriff) 

June  30,  2020  8:06:39  AM  CDT 
June  30,  2020  8:06:48  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Sheriff  Intel,  Sean  Chambers  (Sheriff) 

Sent:  June  30,  2020  8:06:39  AM  CDT 

Received:  June  30,  2020  8:06:47  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Kathryn  Schwendener  (Sheriff),  Sheriff  Intel 

Sent:  June  30,  2020  8:06:39  AM  CDT 

Received:  June  30,  2020  8:06:48  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Neal  Gaynor  (Sheriff) 

Sent:  June  30,  2020  8:06:39  AM  CDT 

Received:  June  30,  2020  8:06:47  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Richard  Brogan  (Sheriff) 

Sent:  June  30,  2020  8:06:39  AM  CDT 

Received:  June  30,  2020  8:06:48  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Jazmond  Watson  (Sheriff) 

Sent:  June  30,  2020  8:06:39  AM  CDT 

Received:  June  30,  2020  8:06:48  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Carl  Price  (Sheriff) 

Sent:  June  30,  2020  8:06:39  AM  CDT 

Received:  June  30,  2020  8:06:47  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Peter  Pon  (Sheriff) 

Sent:  June  30,  2020  8:06:39  AM  CDT 

Received:  June  30,  2020  8:06:48  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

From:  CCSO  Intel  (Sheriff)  <CCSO.INTEL@cookcountyil.gov> 

Bcc:  91 1  Telecommunicators  <AII_91 1_Center@cookcountyil.gov>,  Aaron  Spears 

(Sheriff)  <Aaron.Spears@cookcountyil.gov>,  Abraham  Yasin  (Sheriff) 
<Abraham.Yasin@cookcountyil.gov>,  Amanda  Ruzich  (Sheriff) 
<Amanda.Ruzich@cookcountyil.gov>,  Amar  Patel  (Sheriff) 
<Amar.Patel@cookcountyil.gov>,  Anastasios  Goulos  (Sheriff) 
<Anastasios.Goulos@cookcountyil.gov>,  Andre  Bonhart  (Sheriff) 
<Andre.Bonhart@cookcountyil.gov>,  Angel  Nieves  (Sheriff) 
<Angel.Nieves@cookcountyil.gov>,  Anthony  Colquitt  (Sheriff) 
<Anthony.Colquitt@cookcountyil.gov>,  Anthony  Del  Santo  (Sheriff) 
<Anthony.DelSanto@cookcountyil.gov>,  Ashley  O'Connor  (Sheriff) 
<Ashley.O'Connor@cookcountyil.gov>,  Barbara  Chang  (Sheriff) 
<Barbaro.Chang@cookcountyil.gov>,  Bradley  M  Curry  (Sheriff) 
<Bradley.Curry@cookcountyil.gov>,  Brenda  Humphrey  (Sheriff) 
<Brenda.Humphrey@cookcountyil.gov>,  Brenda  Merle  (Sheriff) 
<Brenda.Merle@cookcountyil.gov>,  Brian  Bialczak  (Sheriff) 
<Brian.Bialczak@cookcountyil.gov>,  Brian  Gibbs  (Sheriff) 
<Brian.Gibbs@cookcountyil.gov>,  Brian  Olano  (Sheriff) 
<Brian.Olano@cookcountyil.gov>,  Carmen  Gercone  (Sheriff) 
<Carmen.Gercone@cookcountyil.gov>,  Carole  Collins  (Sheriff) 
<Carole.Collins@cookcountyil.gov>,  Cathy  Geraghty  (Forest  Preserve  District) 
<cathy.geraghty@cookcountyil.gov>,  Charmaine  Charmelo  (Sheriff) 

<Charmaine. Charmelo@cookcountyil.gov>,  Chris  Kaloudis  (Sheriff) 
<Chris.Kaloudis@cookcountyil.gov>,  Constantine  Jovica  (Sheriff) 
<Constantine.Jovica@cookcountyil.gov>,  Cynthia  Sorrentino  (Sheriff) 
<Cynthia.Sorrentino@cookcountyil.gov>,  Daniel  Cramer  (Sheriff) 
<Daniel.Cramer@cookcountyil.gov>,  Daniel  Gutierrez  (Sheriff) 
<Daniel.Gutierrez@cookcountyil.gov>,  Daniel  Moreci  (Sheriff) 
<Daniel.Moreci@cookcountyil.gov>,  Darren  Ganir  (Sheriff) 
<Darren.Ganir@cookcountyil.gov>,  Darren  Makowski  (Sheriff) 
<Darren.Makowski@cookcountyil.gov>,  Darren  Rycyzyn  (Sheriff) 
<Darren.Rycyzyn@cookcountyil.gov>,  Daryl  Howell  (Sheriff) 
<Daryl.Howell@cookcountyil.gov>,  David  Booker  (Sheriff) 
<David.Booker@cookcountyil.gov>,  David  Chiko  (Sheriff) 
<David.Chiko@cookcountyil.gov>,  Dawn  Guerrero  (Sheriff) 
<Dawn.Guerrero@cookcountyil.gov>,  Debbie  Boecker  (Sheriff) 
<Debbie.Boecker@cookcountyil.gov>,  Denise  Klueg  (Sheriff) 
<Denise.Klueg@cookcountyil.gov>,  Dennis  Nicpan  (Sheriff) 
<Dennis.Nicpan@cookcountyil.gov>,  Doris  Banks-Harrison  (Sheriff) 
<Doris.Banks-Harrison@cookcountyil.gov>,  Drake  Carpenter  (Sheriff) 
<Drake.Carpenter@cookcountyil.gov>,  Edward  Pickell  (Sheriff) 
<Edward.Pickell@cookcountyil.gov>,  Elizabeth  Potter  (Sheriff) 
<Elizabeth.Potter@cookcountyil.gov>,  Eric  Mills  (Sheriff) 
<Eric.Mills@cookcountyil.gov>,  Erica  Queen  (Sheriff) 
<Erica.Queen@cookcountyil.gov>,  Esther  Montanez  (Sheriff) 
<Esther.Montanez@cookcountyil.gov>,  George  Winistorfer  (Sheriff) 
<George.Winistorfer@cookcountyil.gov>,  Georgia  Garcia  (Sheriff) 
<Georgia.Garcia@cookcountyil.gov>,  Geraldo  Medina  (Sheriff) 
<Geraldo.Medina@cookcountyil.gov>,  Gloria  Guerrero  (Sheriff) 
<Gloria.Guerrero@cookcountyil.gov>,  Gregory  Ernst  (Sheriff) 
<Gregory.Ernst@cookcountyil.gov>,  Grisel  Nava  (Sheriff) 
<Grisel.Nava@cookcountyil.gov>,  Henry  Hemphill  (Sheriff) 
<Henry.Hemphill@cookcountyil.gov>,  Henry  McNally  (Sheriff) 
<Henry.Mcnally@cookcountyil.gov>,  Hugh  Walsh  (Sheriff) 
<Hugh.Walsh@cookcountyil.gov>,  Ivette  Perez  (Sheriff) 
<lvette.Perez@cookcountyil.gov>,  Jacqueline  Manna  (Sheriff) 
<Jacqueline.Manna@cookcountyil.gov>,  Jaimee  Kapolnek  (Sheriff) 
<Jaimee.Kapolnek@cookcountyil.gov>,  James  Dillon  (Sheriff) 
<James.Dillon@cookcountyil.gov>,  JAMES  ROACHE  (States  Attorney) 
<JAMES.ROACHE@cookcountyil.gov>,  James  Siroky  (Sheriff) 


<James.Siroky@cookcountyil.gov>,  Janet  Kostanski  (Sheriff) 
<Janet.Kostanski@cookcountyil.gov>,  Jeff  Johnsen  (Sheriff) 
<Jeff.Johnsen@cookcountyil.gov>,  Jeremy  Corning  (Sheriff) 
<Jeremy.Corning@cookcountyil.gov>,  JoAnn  Abruzzo  (Sheriff) 
<JoAnn.Abruzzo@cookcountyil.gov>,  John  Cornier  (Sheriff) 
<John.Cornier@cookcountyil.gov>,  John  Hammond  (Sheriff) 

<John. Hammond@cookcountyil.gov>,  John  Harrington  (Sheriff) 
<John.Harrington@cookcountyil.gov>,  John  Norton  (Sheriff) 
<John.Norton@cookcountyil.gov>,  John  O'Farrell  (Sheriff) 
<John.Ofarrell@cookcountyil.gov>,  John  Scarpelli  (Sheriff) 
<John.Scarpelli@cookcountyil.gov>,  Jonathan  Myslinski  (Sheriff) 
<Jonathan.Myslinski@cookcountyil.gov>,  Jose  Medina  (Sheriff) 
<Jose.Medina@cookcountyil.gov>,  Joseph  Bellettiere  (Sheriff) 
<Joseph.Bellettiere@cookcountyil.gov>,  Joseph  Boyle  (Sheriff) 
<Joseph.Boyle@cookcountyil.gov>,  Joseph  Giunta  (Sheriff) 
<Joseph.Giunta@cookcountyil.gov>,  Joseph  Ryanl  (Sheriff) 
<Joseph.Ryan2@cookcountyil.gov>,  Joseph  Spain  (Sheriff) 
<Joseph.Spain@cookcountyil.gov>,  Joseph  Younan  (Sheriff) 
<Joseph.Younan@cookcountyil.gov>,  Juan  Diaz  (Sheriff) 
<Juan.Diaz@cookcountyil.gov>,  Juan  Salinas  (Sheriff) 
<Juan.Salinas@cookcountyil.gov>,  Kathleen  Kirby  (Sheriff) 
<Kathleen.Kirby@cookcountyil.gov>,  Kathleen  Urbanczyk  (Sheriff) 
<Kathleen.Urbanczyk@cookcountyil.gov>,  Kenneth  Radermacher  (Sheriff) 
<Kenneth.Radermacher@cookcountyil.gov>,  Kevin  Connelly  (Sheriff) 
<Kevin.Connelly@cookcountyil.gov>,  Kimberly  Hofsteadter  (Sheriff) 
<Kimberly.Hofsteadter@cookcountyil.gov>,  Kimberly  Stein  (Sheriff) 
<Kimberly.Stein@cookcountyil.gov>,  Kyle  Halvorson  (Sheriff) 
<Kyle.Halvorson@cookcountyil.gov>,  Larry  Schurig  (Sheriff) 
<Larry.Schurig@cookcountyil.gov>,  Laura  Corrado  (Sheriff) 
<Laura.Corrado@cookcountyil.gov>,  Lawrence  Ostrowski  (Sheriff) 
<Lawrence.Ostrowski@cookcountyil.gov>,  Lawrence  Weston  (Sheriff) 
<Lawrence.Weston@cookcountyil.gov>,  Lee  Ringler  (Sheriff) 
<Lee.Ringler@cookcountyil.gov>,  Leonard  Jagielski  (Sheriff) 
<Leonard.Jagielski@cookcountyil.gov>,  Leroy  Martiniak  (Sheriff) 
<Leroy.Martiniak@cookcountyil.gov>,  Liz  Glick  (Sheriff) 
<Liz.Glick@cookcountyil.gov>,  Mariel  Ramirez  (Sheriff) 
<Mariel.Ramirez@cookcountyil.gov>,  Mark  Modert  (Sheriff) 
<Mark.Modert@cookcountyil.gov>,  Mary  Downes  (Sheriff) 
<Mary.Downes@cookcountyil.gov>,  Mary  McQuillan  (Sheriff) 
<Mary.Mcquillan@cookcountyil.gov>,  Matthew  Cobble  (Sheriff) 
<Matthew.Cobble@cookcountyil.gov>,  Matthew  Jaeky  (Sheriff) 
<Matthew.Jaeky@cookcountyil.gov>,  Maureen  Wasco  (Sheriff) 
<Maureen.Wasco@cookcountyil.gov>,  Melissa  Perez  (Sheriff) 
<Melissa.Perez@cookcountyil.gov>,  Michael  Brady  (Sheriff) 
<Michael.Brady@cookcountyil.gov>,  Michael  Carbone  (Sheriff) 
<Michael.Carbone2@cookcountyil.gov>,  Michael  Fitzpatrick  (Sheriff) 
<Michael.Fitzpatrick@cookcountyil.gov>,  Michael  Flamburis  (Sheriff) 
<Michael.Flamburis@cookcountyil.gov>,  Michael  Grady  (Sheriff) 
<Michael.Grady@cookcountyil.gov>,  Michael  Keane  (Juvenile  Probation) 
<michael.keane@cookcountyil.gov>,  Michael  Knighton  (Sheriff) 
<Michael.Knighton@cookcountyil.gov>,  Michael  Manade  (Sheriff) 
<Michael.Manade@cookcountyil.gov>,  Michael  Me  Hugh  (Sheriff) 
<Michael.McHugh2@cookcountyil.gov>,  Michael  Miller  (Sheriff) 
<Michael.Miller1@cookcountyil.gov>,  Michael  Reed  (Sheriff) 
<Michael.Reed2@cookcountyil.gov>,  Michael  Sheehan  (Sheriff) 
<Michael.Sheehan@cookcountyil.gov>,  Mike  Vallejo  (Sheriff) 
<Mike.Vallejo@cookcountyil.gov>,  Miles  Cooperman  (Sheriff) 
<Miles.Cooperman@cookcountyil.gov>,  Miriam  Rentas  (Sheriff) 
<Miriam.Rentas@cookcountyil.gov>,  Natalie  Camer  (Sheriff) 
<Natalie.Camer@cookcountyil.gov>,  Nicholas  Margarites  (Sheriff) 
<Nicholas.Margarites@cookcountyil.gov>,  Nicole  Pagani  (Sheriff) 
<Nicole.Pagani@cookcountyil.gov>,  Nicole  Rafferty  (Sheriff) 
<Nicole.Rafferty@cookcountyil.gov>,  Patrick  Bradley  (Sheriff) 


<Patrick.Bradley@cookcountyil.gov>,  Patrick  Fitzgerald  (Sheriff) 
<Patrick.Fitzgerald@cookcountyil.gov>,  Patrick  Flannery  (Sheriff) 
<Patrick.Flannery@cookcountyil.gov>,  Patrick  Hecker  (Sheriff) 
<Patrick.Hecker@cookcountyil.gov>,  Patrick  Moerlien  (Sheriff) 
<Patrick.Moerlien@cookcountyil.gov>,  Paul  Kimbrough  (Sheriff) 
<Paul.Kimbrough@cookcountyil.gov>,  Paul  Villanueva  (Sheriff) 
<Paul.Villanueva@cookcountyil.gov>,  Paul  Worthon  (Sheriff) 
<Paul.Worthon@cookcountyil.gov>,  Peter  Pon  (Sheriff) 
<Peter.Pon@cookcountyil.gov>,  Phillip  Mackey  (Sheriff) 
<Phillip.Mackey@cookcountyil.gov>,  Randall  Haber  (Sheriff) 
<Randall.Haber@cookcountyil.gov>,  Rashanda  Carroll  (Sheriff) 
<Rashanda.Carroll@cookcountyil.gov>,  Raymond  Hash  (Sheriff) 
<Raymond.Hash@cookcountyil.gov>,  Richard  Brogan  (Sheriff) 
<Richard.Brogan@cookcountyil.gov>,  Richard  Ellitch  (Sheriff) 
<Richard.Ellitch@cookcountyil.gov>,  Richard  Kim  (Sheriff) 
<Richard.Kim@cookcountyil.gov>,  Richard  O'Brien  (Sheriff) 
<Richard.OBrien1@cookcountyil.gov>,  Richard  Young  (Sheriff) 
<Richard.Young2@cookcountyil.gov>,  Ricky  Soto  (Sheriff) 
<Ricky.Soto@cookcountyil.gov>,  Robert  Bonakowski  (Sheriff) 
<Robert.Bonakowski@cookcountyil.gov>,  Robert  Byrnes  (Sheriff) 
<Robert.Byrnes@cookcountyil.gov>,  Robert  Mazza  (Sheriff) 
<Robert.Mazza@cookcountyil.gov>,  Robert  Reilly  (Sheriff) 
<Robert.Reilly@cookcountyil.gov>,  Rose  Kane  (Sheriff) 
<Rose.Kane@cookcountyil.gov>,  Rotonda  Malone-Cole  (Sheriff) 
<Rotonda.Malone-Cole@cookcountyil.gov>,  Ryan  Killacky  (Sheriff) 
<Ryan.Killacky@cookcountyil.gov>,  Salomon  Martinez  (Sheriff) 
<Salomon.Martinez@cookcountyil.gov>,  Samantha  Thompson  (Sheriff) 
<Samantha. Thompson@cookcountyil.gov>,  Samuel  Cuellar  (Sheriff) 
<Samuel.Cuellar@cookcountyil.gov>,  Sandra  Antczak  (Sheriff) 
<Sandra.Antczak@cookcountyil.gov>,  Alexander  Chew  (Sheriff) 
<Alexander.Chew@cookcountyil.gov>,  Parris  Williams  (Sheriff) 
<Parris.Williams@cookcountyil.gov>,  Adriana  Morales  (Sheriff) 
<Adriana.Morales@cookcountyil.gov>,  Deidre  Williams  (Sheriff) 
<Deidre.Williams@cookcountyil.gov>,  James  Dolehide  (Sheriff) 
<James.Dolehide@cookcountyil.gov>,  Kathryn  Schwendener  (Sheriff) 
<Kathryn.Schwendener@cookcountyil.gov>,  Timothy  Kaufmann  (Sheriff) 
<Timothy.Kaufmann@cookcountyil.gov>,  Cynthia  Lance  (Forest  Preserve 
District)  <Cynthia.Lance@cookcountyil.gov>,  Kelvin  Pope  (Forest  Preserve 
District)  <Kelvin.Pope@cookcountyil.gov>,  Besart  Mila  (Sheriff) 
<Besart.Mila@cookcountyil.gov>,  Andrew  Hein  (Sheriff) 
<Andrew.Hein@cookcountyil.gov>,  Alan  Kicked  (Sheriff) 
<Alan.Kickert@cookcountyil.gov>,  Daniel  Lakowski  (Sheriff) 
<Daniel.Lakowski@cookcountyil.gov>,  Collin  McArdle  (Sheriff) 
<Collin.McArdle@cookcountyil.gov>,  Clifford  Brazzille  (Sheriff) 
<Clifford.Brazzille@cookcountyil.gov>,  Christopher  Suggs  (Sheriff) 
<Christopher.Suggs@cookcountyil.gov>,  Brian  Nyberg  (Sheriff) 
<Brian.Nyberg@cookcountyil.gov>,  Brian  Ashe  (Sheriff) 
<Brian.Ashe@cookcountyil.gov>,  Joseph  Danzl  (Sheriff) 
<Joseph.Danzl@cookcountyil.gov>,  John  Bennett  (Sheriff) 
<John.Bennett@cookcountyil.gov>,  Jazmond  Watson  (Sheriff) 
<Jazmond.Watson@cookcountyil.gov>,  Jason  McCall  (Sheriff) 
<Jason.McCall@cookcountyil.gov>,  Jason  Cianciarulo  (Sheriff) 
<Jason.Cianciarulo@cookcountyil.gov>,  Jasmina  Janjic  (Sheriff) 
<Jasmina.Janjic@cookcountyil.gov>,  Israel  Malave  (Sheriff) 
<lsrael.Malave@cookcountyil.gov>,  Felix  Hernandez  (Sheriff) 
<Felix.Hernandez@cookcountyil.gov>,  Fabio  Valentini  (Sheriff) 
<Fabio.Valentini2@cookcountyil.gov>,  Evan  Fermaint  (Sheriff) 
<Evan.Fermaint@cookcountyil.gov>,  Eric  Schroeder  (Sheriff) 
<Eric.Schroeder@cookcountyil.gov>,  Michael  Falardeau  (Sheriff) 
<Michael.Falardeau@cookcountyil.gov>,  Michael  Bennett  (Sheriff) 
<Michael.Bennett@cookcountyil.gov>,  Maurice  Ashford  (Sheriff) 
<Maurice.Ashford@cookcountyil.gov>,  Maureen  Malloy  (Sheriff) 
<Maureen.Malloy@cookcountyil.gov>,  Kevin  Suchocki  (Sheriff) 


<Kevin.Suchocki@cookcountyil.gov>,  Judie  Sell  (Sheriff) 

<Judie.Sell@cookcountyil.gov>,  Patrick  Noonan  (Sheriff) 
<Patrick.Noonan@cookcountyil.gov>,  Patrick  Kaminski  (Sheriff) 

<Patrick. Kaminski@cookcountyil.gov>,  Nicole  Valerio  (Sheriff) 
<Nicole.Valerio@cookcountyil.gov>,  Neal  Creamer  (Sheriff) 
<Neal.Creamer@cookcountyil.gov>,  Miriam  Santiago  (Sheriff) 
<Miriam.Santiago@cookcountyil.gov>,  Michael  Rowe  (Sheriff) 
<Michael.Rowe@cookcountyil.gov>,  Steven  Valenza  (Sheriff) 
<Steven.Valenza@cookcountyil.gov>,  Steven  Martino  (Sheriff) 
<Steven.Martino@cookcountyil.gov>,  Steve  Jirgal  (Sheriff) 
<Steve.Jirgal@cookcountyil.gov>,  Stephen  Bouffard  (Sheriff) 
<Stephen.Bouffard@cookcountyil.gov>,  Stephan  Maglaya  (Sheriff) 
<Stephan.Maglaya@cookcountyil.gov>,  Shahid  Shekha  (Sheriff) 
<Shahid.Shekha@cookcountyil.gov>,  Sergio  Cervantes  (Sheriff) 
<Sergio.Cervantes@cookcountyil.gov>,  Sean  Chambers  (Sheriff) 
<Sean.Chambers@cookcountyil.gov>,  Scott  Guzik  (Sheriff) 
<Scott.Guzik@cookcountyil.gov>,  Richard  Liboy  (Sheriff) 
<Richard.Liboy@cookcountyil.gov>,  Reginald  Barker  (Sheriff) 
<Reginald.Barker@cookcountyil.gov>,  Perry  Triveri  (Sheriff) 
<Perry.Triveri@cookcountyil.gov>,  Timothy  Blake  (Sheriff) 
<Timothy.Blake@cookcountyil.gov>,  Tia  Parks- Jefferson  (Sheriff)  <Tia.Parks- 
Jefferson@cookcountyil.gov>,  Thomas  Ryan  (Sheriff) 
<Thomas.Ryan2@cookcountyil.gov>,  Thomas  Brunet  (Sheriff) 
<Thomas.Brunet@cookcountyil.gov>,  Tarry  Williams  (Sheriff) 
<Tarry.Williams@cookcountyil.gov>,  Steven  Williams  (Sheriff) 
<Steven.Williams@cookcountyil.gov>,  Victoria  Winford  (Sheriff) 
<Victoria.Winford@cookcountyil.gov>,  Victoria  Haig  (Sheriff) 
<Victoria.Haig@cookcountyil.gov>,  Valerie  Spurlock  (Sheriff) 
<Valerie.Spurlock@cookcountyil.gov>,  Valerie  Koedyker  (Sheriff) 
<Valerie.Koedyker@cookcountyil.gov>,  Tracy  Cavanaugh  (Sheriff) 
<Tracy.Cavanaugh@cookcountyil.gov>,  Timothy  Cook  (Sheriff) 
<Timothy.Cook@cookcountyil.gov>,  Zelda  Whittier  (Sheriff) 
<Zelda.Whittler@cookcountyil.gov>,  William  Shepski-Lindsted  (Sheriff) 
<William.Shepski-Lindsted@cookcountyil.gov>,  William  Scanlon  (Sheriff) 
<William.Scanlon@cookcountyil.gov>,  William  Behenna  (Sheriff) 
<William.Behenna@cookcountyil.gov>,  Wanda  Gastile  (Sheriff) 
<Wanda.Gastile@cookcountyil.gov>,  CCSO  EM 
<ccso.em@cookcountyil.gov>,  Eyman  Zabadneh  (Sheriff) 
<Eyman.Zabadneh@cookcountyil.gov>,  Stefana  Castillo  (Sheriff) 
<Stefana.Castillo@cookcountyil.gov>,  Adnan  Memon  (Sheriff) 
<Adnan.Memon@cookcountyil.gov>,  Douglas  Maclean  (Sheriff) 
<Douglas.Maclean2@cookcountyil.gov>,  Nikolas  Hadjian  (Sheriff) 
<Nikolas.Hadjian@cookcountyil.gov>,  Michael  Bernardini  (Juvenile  Temporary 
Detention  Center)  <Michael.Bernardini@cookcountyil.gov>,  Robert  Lunk 
(Sheriff)  <Robert. Lunk@cookcountyil.gov> 

Sent:  June  30,  2020  8:06:39  AM  CDT 

Received:  June  30,  2020  8:06:41  AM  CDT 

Attachments:  (U--FOUO)  I  IB  -  Criminal  Hackers  Target  US  Law  Enforcement  Data 

06262020.pdf 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated 
June  29,  2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a 
hack-and-leak  operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support 
of  or  in  response  to  nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years 
of  data  from  200  police  departments,  fusion  centers,  and  other  law  enforcement  training  and  support 
resources  around  the  globe,  according  to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack- 
and-leak  activity  against  the  Russian  Government. 


If  you  no  longer  wish  to  be  on  this  distribution  list,  please  send  an  email  to  ccso.intel@cookcountyil.gov  to  discontinue  receiving 
these  emails.  If  you  would  like  any  member  under  your  command  to  receive  these  emails,  please  send  an  email  to 
ccso.intel@cookcormtyil.gov  and  include  their  name,  title  and  email  address  in  the  body  of  the  request. 


Cook  County  Sheriffs  Office 
Strategic  Operations  Center 
3026  S.  California  Avenue 
Building  5,  2nd  Floor 
Chicago,  IL.  60608 
Office:  773-674-2694  or  8477 
Fax:  773-674-4797 


THIS  IS  A  CONFIDENTIAL  LAW  ENFORCEMENT  COMMUNICATION.  The  contents  of  this  e-mail  message  and  any 
attachments  are  intended  solely  for  the  addressee(s)  named  in  this  message.  This  communication  is  intended  to  be  and  to  remain 
confidential.  If  you  are  not  the  intended  recipient  of  this  message,  or  if  this  message  has  been  addressed  to  you  in  error,  please 
immediately  alert  the  sender  by  reply  e-mail  and  then  delete  this  message  and  its  attachments.  Do  not  deliver,  distribute,  transmit 
or  copy  this  message  and/or  any  attachments  and  if  you  are  not  the  intended  recipient,  do  not  disclose  the  contents  or  take  any 
action  relative  to  the  information  contained  in  this  communication  and/or  attachments.  This  e-mail  and  any  attached  documents 
may  contain  For  Official  Use  Only  and/or  Law  Enforcement  Sensitive  material  and  should  not  be  disseminated  outside  of  official 
law  enforcement  channels.  The  information  contained  in  this  message  as  well  as  any  attachments  shall  not  be  released  to  the 
media  or  the  general  public. 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

Sent:  June  30,  2020  8:07:20  AM  CDT 

Received:  June  30,  2020  8:07:29  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Sheriff  Intel 

Sent:  June  30,  2020  8:07:20  AM  CDT 

Received:  June  30,  2020  8:07:26  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Adam  Murphy  (Sheriff) 

Sent:  June  30,  2020  8:07:20  AM  CDT 

Received:  June  30,  2020  8:07:26  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Juan  Claudio  (Sheriff) 

Sent:  June  30,  2020  8:07:20  AM  CDT 

Received:  June  30,  2020  8:07:26  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Andre  Blue  (Sheriff) 

Sent:  June  30,  2020  8:07:20  AM  CDT 

Received:  June  30,  2020  8:07:29  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Joseph  Scofield  (Sheriff) 

Sent:  June  30,  2020  8:07:20  AM  CDT 

Received:  June  30,  2020  8:07:26  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Jaunesh  Contreras  (Sheriff) 

Sent:  June  30,  2020  8:07:20  AM  CDT 

Received:  June  30,  2020  8:07:29  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Joseph  Nicholas  (Sheriff) 

Sent:  June  30,  2020  8:07:20  AM  CDT 

Received:  June  30,  2020  8:07:27  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Antoinette  Bradley  (Sheriff) 

Sent:  June  30,  2020  8:07:20  AM  CDT 

Received:  June  30,  2020  8:07:27  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Arthur  Jackson  (Sheriff) 

Sent:  June  30,  2020  8:07:20  AM  CDT 

Received:  June  30,  2020  8:07:26  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  David  Cammack  (Sheriff) 

Sent:  June  30,  2020  8:07:20  AM  CDT 

Received:  June  30,  2020  8:07:27  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Jasmina  Janjic  (Sheriff) 

Sent:  June  30,  2020  8:07:20  AM  CDT 

Received:  June  30,  2020  8:07:26  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Joseph  Rosenau  (Sheriff) 

Sent:  June  30,  2020  8:07:20  AM  CDT 

Received:  June  30,  2020  8:07:26  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Gustavo  Jimenez  (Sheriff) 

Sent:  June  30,  2020  8:07:20  AM  CDT 

Received:  June  30,  2020  8:07:28  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  John  Konrad  (Sheriff) 

Sent:  June  30,  2020  8:07:20  AM  CDT 

Received:  June  30,  2020  8:07:29  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Adrian  Molina  (Sheriff) 

Sent:  June  30,  2020  8:07:20  AM  CDT 

Received:  June  30,  2020  8:07:26  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Kevin  O'Donnell  (Sheriff) 

Sent:  June  30,  2020  8:07:20  AM  CDT 

Received:  June  30,  2020  8:07:26  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Christopher  Harvey  (Sheriff) 

Sent:  June  30,  2020  8:07:20  AM  CDT 

Received:  June  30,  2020  8:07:26  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Jerome  Ryan  (Sheriff) 

Sent:  June  30,  2020  8:07:20  AM  CDT 

Received:  June  30,  2020  8:07:26  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Brian  Staudt  (Sheriff) 

Sent:  June  30,  2020  8:07:20  AM  CDT 

Received:  June  30,  2020  8:07:26  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Joseph  Phillips  (Sheriff) 

Sent:  June  30,  2020  8:07:20  AM  CDT 

Received:  June  30,  2020  8:07:27  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Fulvio  Compagnone  (Sheriff) 

Sent:  June  30,  2020  8:07:20  AM  CDT 

Received:  June  30,  2020  8:07:26  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

From:  CCSO  Intel  (Sheriff)  <CCSO.INTEL@cookcountyil.gov> 

Bcc:  Aaron  Cadena  (Sheriff)  <Aaron.Cadena@cookcountyil.gov>,  Aaron  Spears 

(Sheriff)  <Aaron.Spears@cookcountyil.gov>,  Abel  Torres  (Sheriff) 
<Abel.Torres@cookcountyil.gov>,  Abelardo  Mercado  (Sheriff) 
<Abelardo.Mercado@cookcountyil.gov>,  Adam  Dowdell  (Sheriff) 
<Adam.Dowdell@cookcountyil.gov>,  Adam  Lachecki  (Sheriff) 
<Adam.Lachecki@cookcountyil.gov>,  Adam  Lemons  (Sheriff) 
<Adam.Lemons@cookcountyil.gov>,  Adam  Murphy  (Sheriff) 
<Adam.Murphy@cookcountyil.gov>,  Adam  Stafiera  (Sheriff) 
<Adam.Stafiera@cookcountyil.gov>,  Adrian  Cerchez  (Sheriff) 
<Adrian.Cerchez@cookcountyil.gov>,  Adrian  Molina  (Sheriff) 
<Adrian.Molina@cookcountyil.gov>,  Adrian  Sandoval  (Sheriff) 
<Adrian.Sandoval@cookcountyil.gov>,  Aisha  Wade  (Sheriff) 
<Aisha.Wade@cookcountyil.gov>,  Alan  Kicked  (Sheriff) 
<Alan.Kickert@cookcountyil.gov>,  Aleshia  Maurer  (Sheriff) 
<Aleshia.Maurer@cookcountyil.gov>,  Alexander  Brodie  (Sheriff) 
<Alexander.Brodie@cookcountyil.gov>,  Alexandra  Bouziotis  (Sheriff) 
<Alexandra.Bouziotis@cookcountyil.gov>,  Alfredo  Garcia  (Sheriff) 
<Alfredo.Garcia@cookcountyil.gov>,  Allen  Giacchetti  (Sheriff) 
<Allen.Giacchetti@cookcountyil.gov>,  Alvin  Coleman  (Sheriff) 
<Alvin.Coleman@cookcountyil.gov>,  Amar  Patel  (Sheriff) 
<Amar.Patel@cookcountyil.gov>,  Ambrose  Kelly  (Sheriff) 
<Ambrose.Kelly@cookcountyil.gov>,  Amy  Lilliebridge  (Sheriff) 
<Amy.Lilliebridge@cookcountyil.gov>,  Ana  Rivera  (Sheriff) 
<Ana.Rivera@cookcountyil.gov>,  Andre  Blue  (Sheriff) 
<Andre.Blue@cookcountyil.gov>,  Andrew  Douvris  (Sheriff) 
<Andrew.Douvris@cookcountyil.gov>,  Andrew  Gutter  (Sheriff) 
<Andrew.Gutter@cookcountyil.gov>,  Andrew  Tucker  (Sheriff) 
<Andrew.Tucker@cookcountyil.gov>,  Angel  Garcia  (Sheriff) 
<Angel.Garcia2@cookcountyil.gov>,  Angela  Thornton  (Sheriff) 
<Angela.Thornton@cookcountyil.gov>,  Anita  Dix-Lindsey  (Sheriff)  <Anita.Dix- 
Lindsey@cookcountyil.gov>,  Anna  Wilk  (Sheriff) 

<Anna.Wilk@cookcountyil.gov>,  Anthony  Aguirre  (Sheriff) 
<Anthony.Aguirre@cookcountyil.gov>,  Anthony  Burns  (Sheriff) 
<Anthony.Burns@cookcountyil.gov>,  Anthony  Cortesi  (Sheriff) 
<Anthony.Cortesi@cookcountyil.gov>,  Anthony  Kozlar  (Sheriff) 
<Anthony.Kozlar@cookcountyil.gov>,  Anthony  Licata  (Sheriff) 
<Anthony.Licata2@cookcountyil.gov>,  Anthony  Ochoa  (Sheriff) 
<Anthony.Ochoa@cookcountyil.gov>,  Anthony  Roche  (Sheriff) 
<Anthony.Roche@cookcountyil.gov>,  Anthony  Schickel  (Sheriff) 
<Anthony.Schickel@cookcountyil.gov>,  Anthony  Stack  (Sheriff) 
<Anthony.Stack@cookcountyil.gov>,  Antoinette  Bradley  (Sheriff) 
<Antoinette.Bradley@cookcountyil.gov>,  Antwann  Boyd  (Sheriff) 
<Antwann.Boyd@cookcountyil.gov>,  Armando  Gutierrez  (Sheriff) 
<Armando.Gutierrez2@cookcountyil.gov>,  Armando  Gutierrez  (Sheriff) 
<Armando.Gutierrez@cookcountyil.gov>,  Arthur  Jackson  (Sheriff) 
<Arthur.Jackson@cookcountyil.gov>,  Arthur  Taylor  (Sheriff) 
<Arthur.Taylor@cookcountyil.gov>,  Augie  Fabela  (Sheriff) 
<Augie.Fabela@cookcountyil.gov>,  Barbara  Dymitrowicz  (Sheriff) 
<Barbara.Dymitrowicz@cookcountyil.gov>,  Barbara  Perduto  (Sheriff) 
<Barbara.Perduto@cookcountyil.gov>,  Beatrice  Winfert-Quan  (Sheriff) 
<Beatrice.Winfert-Quan@cookcountyil.gov>,  Beatriz  Vigil  (Sheriff) 
<Beatriz.Vigil3@cookcountyil.gov>,  Benjamin  Sullivan  (Sheriff) 
<Benjamin.Sullivan@cookcountyil.gov>,  Benjamin  VonOhlen  (Sheriff) 
<Benjamin.Vonohlen@cookcountyil.gov>,  Beverly  Austin  (Sheriff) 
<Beverly.Austin@cookcountyil.gov>,  Bonnie  Busching  (Sheriff) 
<Bonnie.Busching@cookcountyil.gov>,  Brandon  Ducray  (Sheriff) 
<Brandon.Ducray@cookcountyil.gov>,  Brenda  McKendrick  (Sheriff) 
<Brenda.Mckendrick@cookcountyil.gov>,  Brendan  Behan  (Sheriff) 
<Brendan.Behan@cookcountyil.gov>,  Brian  Abels  (Sheriff) 


<Brian.Abels@cookcountyil.gov>,  Brian  Atkinson  (Sheriff) 
<Brian.Atkinson@cookcountyil.gov>,  Brian  Bonarek  (Sheriff) 
<Brian.Bonarek@cookcountyil.gov>,  Brian  Dignan  (Sheriff) 
<Brian.Dignan@cookcountyil.gov>,  Brian  Hartsfield  (Sheriff) 
<Brian.Hartsfield@cookcountyil.gov>,  Brian  Helstern  (Sheriff) 
<Brian.Helstern@cookcountyil.gov>,  Brian  Manthey  (Sheriff) 
<Brian.Manthey@cookcountyil.gov>,  Brian  Matos  (Sheriff) 
<Brian.Matos@cookcountyil.gov>,  Brian  McNamara  (Sheriff) 
<Brian.Mcnamara@cookcountyil.gov>,  Brian  Staudt  (Sheriff) 
<Brian.Staudt@cookcountyil.gov>,  Brian  Toner  (Sheriff) 
<Brian.Toner@cookcountyil.gov>,  Brian  Toosley  (Sheriff) 
<Brian.Toosley@cookcountyil.gov>,  Brian  White  (Sheriff) 
<Brian.White@cookcountyil.gov>,  Brittney  Blair  (Sheriff) 
<Brittney.Blair@cookcountyil.gov>,  Bruce  Steinke  (Sheriff) 
<Bruce.Steinke@cookcountyil.gov>,  Bryant  Walker  (Sheriff) 
<Bryant.Walker@cookcountyil.gov>,  Cameron  Pon  (Sheriff) 
<Cameron.Pon@cookcountyil.gov>,  Carl  Campbell  (Sheriff) 
<Carl.Campbell@cookcountyil.gov>,  Carl  Oviedo  (Sheriff) 

<Carl. Oviedo@cookcountyil.gov>,  Carl  Shaw  (Sheriff) 
<Carl.Shaw@cookcountyil.gov>,  Carlos  Martinez  (Sheriff) 
<Carlos.Martinez@cookcountyil.gov>,  Carmelo  Reillo  (Sheriff) 
<Carmelo.Reillo@cookcountyil.gov>,  Cassy  Poirier  (Sheriff) 
<Cassy.Poirier@cookcountyil.gov>,  Catherine  Belluomini  (Sheriff) 
<Catherine.Belluomini@cookcountyil.gov>,  Catherine  DiGiovanni  (Sheriff) 
<Catherine.DiGiovanni@cookcountyil.gov>,  Catherine  Domine  (Sheriff) 
<Catherine.Domine@cookcountyil.gov>,  Catherine  Fitzgerald  (Sheriff) 
<Catherine.Fitzgerald@cookcountyil.gov>,  Catherine  Mellett  (Sheriff) 
<Catherine.Mellett@cookcountyil.gov>,  Cathy  Ryan  (Sheriff) 
<Cathy.Ryan@cookcountyil.gov>,  Cedric  Brantley  (Sheriff) 
<Cedric.Brantley@cookcountyil.gov>,  Cedric  Me  Cloud  (Sheriff) 
<Cedric.Mccloud@cookcountyil.gov>,  Cesar  Carbajal  (Sheriff) 
<Cesar.Carbajal@cookcountyil.gov>,  Chad  Bonen  (Sheriff) 
<Chad.Bonen@cookcountyil.gov>,  Charles  Graf  (Sheriff) 
<Charles.Graf@cookcountyil.gov>,  Charles  Henderson  (Sheriff) 
<Charles.Henderson@cookcountyil.gov>,  Charles  Little  (Sheriff) 
<Charles.Little@cookcountyil.gov>,  Charles  Olson  (Sheriff) 
<Charles.Olson@cookcountyil.gov>,  Christie  Urso  (Sheriff) 
<Christie.Urso@cookcountyil.gov>,  Christina  Nedved  (Sheriff) 
<Christina.Nedved@cookcountyil.gov>,  Christine  Bertucci  (Sheriff) 
<Christine.Bertucci@cookcountyil.gov>,  Christine  Gallagher  (Sheriff) 
<Christine.Gallagher@cookcountyil.gov>,  Christine  Miller  (Sheriff) 
<Christine.Miller@cookcountyil.gov>,  Christopher  Arocho  (Sheriff) 
<Christopher.Arocho@cookcountyil.gov>,  Christopher  Boyle  (Sheriff) 
<Christopher.Boyle@cookcountyil.gov>,  Christopher  Calhoun  (Sheriff) 
<Christopher.Calhoun@cookcountyil.gov>,  Christopher  Dangles  (Sheriff) 
<Christopher.Dangles@cookcountyil.gov>,  Christopher  Garcia  (Sheriff) 
<Christopher.Garcia1@cookcountyil.gov>,  Christopher  Harris  (Sheriff) 
<Christopher.Harris@cookcountyil.gov>,  Christopher  Harvey  (Sheriff) 
<Christopher.Harvey@cookcountyil.gov>,  Christopher  Imhof  (Sheriff) 
<Christopher.lmhof@cookcountyil.gov>,  Christopher  Lanuti  (Sheriff) 
<Christopher.Lanuti@cookcountyil.gov>,  Christopher  McDonough  (Sheriff) 
<Christopher.Mcdonough@cookcountyil.gov>,  Christopher  Olejarz  (Sheriff) 
<Christopher.Olejarz@cookcountyil.gov>,  Christopher  Rago  (Sheriff) 
<Christopher.Rago@cookcountyil.gov>,  Christopher  Suggs  (Sheriff) 
<Christopher.Suggs@cookcountyil.gov>,  Cierra  Thurman  (Sheriff) 
<Cierra.Thurman@cookcountyil.gov>,  Cody  Lettiere  (Sheriff) 
<Cody.Lettiere@cookcountyil.gov>,  Conley  Dyer  (Sheriff) 
<Conley.Dyer@cookcountyil.gov>,  Conrad  Edgett  (Sheriff) 
<Conrad.Edgett@cookcountyil.gov>,  Corey  Russell  (Sheriff) 
<Corey.Russell@cookcountyil.gov>,  Craig  Wilk  (Sheriff) 
<Craig.Wilk@cookcountyil.gov>,  Dan  Nowotarski  (Sheriff) 
<Dan.Nowotarski@cookcountyil.gov>,  Daniel  Alvarado  (Sheriff) 
<Daniel.Alvarado@cookcountyil.gov>,  Daniel  Borosz  (Sheriff) 


<Daniel.Borosz@cookcountyil.gov>,  Daniel  Burke  (Sheriff) 
<Daniel.Burke@cookcountyil.gov>,  Daniel  Codd  (Sheriff) 
<Daniel.Codd@cookcountyil.gov>,  Daniel  Dehoyos  (Sheriff) 
<Daniel.DeHoyos@cookcountyil.gov>,  Daniel  Gmiterek  (Sheriff) 
<Daniel.Gmiterek@cookcountyil.gov>,  Daniel  Keserich  (Sheriff) 
<Daniel.Keserich@cookcountyil.gov>,  Daniel  Lopez  (Sheriff) 
<Daniel.Lopez@cookcountyil.gov>,  Daniel  Mo  (Sheriff) 
<Daniel.Mo@cookcountyil.gov>,  Daniel  Pollard  (Sheriff) 
<Daniel.Pollard@cookcountyil.gov>,  Daniel  Redican  (Sheriff) 
<Daniel.Redican@cookcountyil.gov>,  Daniel  Schaller  (Sheriff) 
<Daniel.Schaller@cookcountyil.gov>,  Daniel  Strong  (Sheriff) 
<Daniel.Strong@cookcountyil.gov>,  Daniel  Woods  (Sheriff) 
<Daniel.Woods@cookcountyil.gov>,  Darryl  Anthony  (Sheriff) 
<Darryl.Anthony@cookcountyil.gov>,  Darryl  Ashley  (Sheriff) 
<Darryl.Ashley@cookcountyil.gov>,  Darryl  Manning  (Sheriff) 
<Darryl.Manning@cookcountyil.gov>,  Daryl  Demro  (Sheriff) 
<Daryl.Demro@cookcountyil.gov>,  Dave  Hardy  (Sheriff) 
<Dave.Hardy@cookcountyil.gov>,  David  Baez  (Sheriff) 
<David.Baez@cookcountyil.gov>,  David  Bily  (Sheriff) 
<David.Bily@cookcountyil.gov>,  David  Buffham  (Sheriff) 
<David.Buffham@cookcountyil.gov>,  David  Cammack  (Sheriff) 
<David.Cammack@cookcountyil.gov>,  David  Carroll  (Sheriff) 
<David.Carroll@cookcountyil.gov>,  David  Delgado  (Sheriff) 
<David.Delgado1@cookcountyil.gov>,  David  Krok  (Sheriff) 
<David.Krok@cookcountyil.gov>,  David  Lomax  (Sheriff) 
<David.Lomax@cookcountyil.gov>,  David  Ribaldo  (Sheriff) 
<David.Ribaldo@cookcountyil.gov>,  David  Sokolowski  (Sheriff) 
<David.Sokolowski@cookcountyil.gov>,  David  Stanly  (Sheriff) 
<David.Stanly@cookcountyil.gov>,  David  Stiak  (Sheriff) 
<David.Stiak@cookcountyil.gov>,  David  Tuzim  (Sheriff) 
<David.Tuzim@cookcountyil.gov>,  David  Witkowski  (Sheriff) 
<David.Witkowski@cookcountyil.gov>,  Dedra  Cummins  (Sheriff) 

<Dedra. Cummins@cookcountyil.gov>,  Delisa  Spears  (Sheriff) 
<Delisa.Spears@cookcountyil.gov>,  Demetrius  Nichols  (Sheriff) 
<Demetrius.Nichols@cookcountyil.gov>,  Denise  Banda  (Sheriff) 
<Denise.Banda@cookcountyil.gov>,  Denise  Demichel  (Sheriff) 
<Denise.Demichel@cookcountyil.gov>,  Deon  Tate  (Sheriff) 
<Deon.Tate@cookcountyil.gov>,  Derek  Fabian  (Sheriff) 
<Derek.Fabian@cookcountyil.gov>,  Derrick  Trice  (Sheriff) 
<Derrick.Trice@cookcountyil.gov>,  Devlin  Gray  (Sheriff) 
<Devlin.Gray@cookcountyil.gov>,  Diane  Haras  (Sheriff) 
<Diane.Haras@cookcountyil.gov>,  Dimas  Hernandez  (Sheriff) 
<Dimas.Hernandez@cookcountyil.gov>,  Dion  Trotter  (Sheriff) 
<Dion.Trotter@cookcountyil.gov>,  Dominic  Boggia  (Sheriff) 
<Dominic.Boggia@cookcountyil.gov>,  Dominique  Deal  (Sheriff) 
<Dominique.Deal@cookcountyil.gov>,  Don  Stewart  (Sheriff) 
<Don.Stewart@cookcountyil.gov>,  Donald  Buczkowski  (Sheriff) 
<Donald.Buczkowski@cookcountyil.gov>,  Donald  Harris  (Sheriff) 
<Donald.Harris@cookcountyil.gov>,  Dorian  Swain  (Sheriff) 
<Dorian.Swain@cookcountyil.gov>,  Douglas  Crawford  (Sheriff) 
<Douglas.Crawford@cookcountyil.gov>,  Douglas  Schultz  (Sheriff) 
<Douglas.Schultz@cookcountyil.gov>,  Eddie  Ishoo  (Sheriff) 
<Eddie.lshoo@cookcountyil.gov>,  Edmundo  Hernandez  (Sheriff) 
<Edmundo.Hernandez@cookcountyil.gov>,  Eduardo  Hower  (Sheriff) 
<Eduardo.Hower@cookcountyil.gov>,  Edward  Barksdale  (Sheriff) 
<Edward.Barksdale@cookcountyil.gov>,  Edward  Graney  (Sheriff) 
<Edward.Graney@cookcountyil.gov>,  Edward  Lewandowski  (Sheriff) 
<Edward.Lewandowski@cookcountyil.gov>,  Eevandia  Weatherly  (Sheriff) 
<Eevandia.Weatherly@cookcountyil.gov>,  Efrain  Mata  (Sheriff) 
<Efrain.Mata@cookcountyil.gov>,  Eliezer  Pacheco  (Sheriff) 
<Eliezer.Pacheco@cookcountyil.gov>,  Elizabeth  Collins  (Sheriff) 
<Elizabeth.Collins@cookcountyil.gov>,  Elizabeth  McCarthy  (Sheriff) 
<Elizabeth.McCarthy@cookcountyil.gov>,  Elliott  Feliciano  (Sheriff) 


<Elliott.Feliciano@cookcountyil.gov>,  Elliott  Reyes  (Sheriff) 
<Elliott.Reyes@cookcountyil.gov>,  Enrique  Nieves  (Sheriff) 
<Enrique.Nieves@cookcountyil.gov>,  Enver  Vejzovic  (Sheriff) 
<Enver.Vejzovic@cookcountyil.gov>,  Eric  Burnson  (Sheriff) 
<Eric.Burnson@cookcountyil.gov>,  Eric  Maurer  (Sheriff) 
<Eric.Maurer@cookcountyil.gov>,  Eric  Przybycien  (Sheriff) 
<Eric.Przybycien@cookcountyil.gov>,  Eric  Sellers  (Sheriff) 
<Eric.Sellers@cookcountyil.gov>,  Eric  Siciliano  (Sheriff) 
<Eric.Siciliano@cookcountyil.gov>,  Erik  Roedel  (Sheriff) 
<Erik.Roedel@cookcountyil.gov>,  Erika  Rodriguez  (Sheriff) 
<Erika.Rodriguez2@cookcountyil.gov>,  Erin  Hamilton  (Sheriff) 
<Erin.Hamilton@cookcountyil.gov>,  Eryn  T  Hedderman  (Sheriff) 
<Eryn.Hedderman@cookcountyil.gov>,  Eugene  Butler  (Sheriff) 
<Eugene.Butler@cookcountyil.gov>,  Eyad  Awad  (Sheriff) 
<Eyad.Awad@cookcountyil.gov>,  Faliata  Holman  (Sheriff) 
<Faliata.Holman@cookcountyil.gov>,  Faviana  Leon  (Sheriff) 
<Faviana.Leon@cookcountyil.gov>,  Felix  Arvelo  (Sheriff) 
<Felix.Arvelo@cookcountyil.gov>,  Foster  Bradley  (Sheriff) 
<Foster.Bradley@cookcountyil.gov>,  Francisco  Ruiz  (Sheriff) 
<Francisco.Ruiz@cookcountyil.gov>,  Frank  Caridei  (Sheriff) 
<Frank.Caridei@cookcountyil.gov>,  Frank  D'oronzo  (Sheriff) 
<Frank.Doronzo@cookcountyil.gov>,  Frank  Medrys  (Sheriff) 
<Frank.Medrys@cookcountyil.gov>,  Frank  Washington  (Sheriff) 
<Frank.Washington@cookcountyil.gov>,  Frank  Wisniewski  (Sheriff) 
<Frank.Wisniewski@cookcountyil.gov>,  Frederick  Nowaczyk  (Sheriff) 
<Frederick.Nowaczyk@cookcountyil.gov>,  Froylan  Mena  (Sheriff) 
<Froylan.Mena@cookcountyil.gov>,  Fulvio  Compagnone  (Sheriff) 
<Fulvio.Compagnone@cookcountyil.gov>,  Gary  Contreras  (Sheriff) 
<Gary.Contreras@cookcountyil.gov>,  Gary  Newsom  (Sheriff) 
<Gary.Newsom@cookcountyil.gov>,  Gary  Rizzo  (Sheriff) 
<Gary.Rizzo@cookcountyil.gov>,  Genevieve  Voves  (Sheriff) 
<Genevieve.Voves@cookcountyil.gov>,  George  Anton  (Sheriff) 
<George.Anton@cookcountyil.gov>,  George  Marks  (Sheriff) 
<George.Marks@cookcountyil.gov>,  George  Velisaris  (Sheriff) 
<George.Velisaris@cookcountyil.gov>,  Gerald  Chickerillo  (Sheriff) 
<Gerald.Chickerillo@cookcountyil.gov>,  Gilberto  Romero  (Sheriff) 
<Gilberto.Romero@cookcountyil.gov>,  Ginny  Georgantas  (Sheriff) 
<Ginny.Georgantas@cookcountyil.gov>,  Giovanni.Veitkus@cookcountyil.gov, 
Gordon  Brewer  (Sheriff)  <Gordon.Brewer@cookcountyil.gov>,  Grazyna 
Moczarna  (Sheriff)  <Grazyna.Moczarna@cookcountyil.gov>,  Gregory  Barron 
(Sheriff)  <Gregory.Barron@cookcountyil.gov>,  Gregory  Kulasa  (Sheriff) 
<Gregory.Kulasa@cookcountyil.gov>,  Gregory  Sandquist  (Sheriff) 
<Gregory.Sandquist@cookcountyil.gov>,  Gregory  Vlahos  (Sheriff) 
<Gregory.Vlahos@cookcountyil.gov>,  Gustavo  Jimenez  (Sheriff) 
<Gustavo.Jimenez@cookcountyil.gov>,  Harry  Vance  (Sheriff) 
<Harry.Vance@cookcountyil.gov>,  Heather  Bock  (Sheriff) 
<Heather.Bock@cookcountyil.gov>,  Heather  Jaycox  (Sheriff) 
<Heather.Jaycox@cookcountyil.gov>,  Hector  Mendez  (Sheriff) 
<Hector.Mendez@cookcountyil.gov>,  Helen  O'Connor  (Sheriff) 
<Helen.O'connor@cookcountyil.gov>,  Helen  Siaj  (Sheriff) 
<Helen.Siaj@cookcountyil.gov>,  Henry  Macugowski  (Sheriff) 
<Henry.Macugowski@cookcountyil.gov>,  Henry  Rush  (Sheriff) 
<Henry.Rush@cookcountyil.gov>,  Henry  Washington  (Sheriff) 
<Henry.Washington@cookcountyil.gov>,  Irene  Salinas  (Sheriff) 
<lrene.Salinas@cookcountyil.gov>,  Iseano  McDonald  (Sheriff) 
<lseano.Mcdonald@cookcountyil.gov>,  Issac  Thomas  (Sheriff) 
<lssac.Thomas@cookcountyil.gov>,  Ivan  Salva  (Sheriff) 
<lvan.Salva@cookcountyil.gov>,  Jacob  Moran  (Sheriff) 
<Jacob.Moran@cookcountyil.gov>,  Jacqueline  Brown  (Sheriff) 
<Jacqueline.Brown2@cookcountyil.gov>,  Jacqueline  Lazzara  (Sheriff) 
<Jacqueline.Lazzara@cookcountyil.gov>,  Jae  Bae  (Sheriff) 
<Jae.Bae@cookcountyil.gov>,  Jae  Bael  (Sheriff) 
<Jae.Bae2@cookcountyil.gov>,  Jaime  Martinez  (Sheriff) 


<Jaime.Martinez2@cookcountyil.gov>,  Jaime  Martinez  (Sheriff) 
<Jaime.Martinez3@cookcountyil.gov>,  James  Anichini  (Sheriff) 
<James.Anichini@cookcountyil.gov>,  James  Bolek  (Sheriff) 
<James.Bolek@cookcountyil.gov>,  James  Davis  (Sheriff) 
<James.Davis@cookcountyil.gov>,  James  Draz  (Sheriff) 
<James.Draz@cookcountyil.gov>,  James  Goodman  (Sheriff) 
<James.Goodman@cookcountyil.gov>,  James  Gosling  (Sheriff) 
<James.Gosling@cookcountyil.gov>,  James  Harris  (Sheriff) 
<James.Harris@cookcountyil.gov>,  James  Hughes  (Sheriff) 
<James.Hughes@cookcountyil.gov>,  James  Me  Caffrey  (Sheriff) 
<James.Mccaffrey@cookcountyil.gov>,  James  Pacetti  (Sheriff) 
<James.Pacetti@cookcountyil.gov>,  James  Plybon  (Sheriff) 
<James.Plybon@cookcountyil.gov>,  James  Scannell  (Sheriff) 
<James.Scannell@cookcountyil.gov>,  James  Torelli  (Sheriff) 
<James.Torelli@cookcountyil.gov>,  Jami  Koprowski  (Sheriff) 
<Jami.Koprowski@cookcountyil.gov>,  Jarius  Dixon  (Sheriff) 
<Jarius.Dixon@cookcountyil.gov>,  Jaron  Lee  (Sheriff) 
<Jaron.Lee@cookcountyil.gov>,  Jasmina  Janjic  (Sheriff) 
<Jasmina.Janjic@cookcountyil.gov>,  Jason  Broadway  (Sheriff) 
<Jason.Broadway@cookcountyil.gov>,  Jason  Doeslaere  (Sheriff) 
<Jason.Doeslaere@cookcountyil.gov>,  Jason  Moran  (Sheriff) 
<Jason.Moran@cookcountyil.gov>,  Jason  O'Malley  (Sheriff) 
<Jason.O'Malley@cookcountyil.gov>,  Jason  Schmidt  (Sheriff) 
<Jason.Schmidt@cookcountyil.gov>,  Jasper  Nelson  (Sheriff) 
<Jasper.Nelson@cookcountyil.gov>,  Jaunesh  Contreras  (Sheriff) 
<Jaunesh.Contreras@cookcountyil.gov>,  Javier  Alvarez  (Sheriff) 
<Javier.Alvarez@cookcountyil.gov>,  Jeff  Guay  (Sheriff) 
<Jeff.Guay@cookcountyil.gov>,  Jeffrey  Ansted  (Sheriff) 
<Jeffrey.Ansted@cookcountyil.gov>,  Jeffrey  Ramos  (Sheriff) 
<Jeffrey.Ramos@cookcountyil.gov>,  Jeffrey  Trost  (Sheriff) 
<Jeffrey.Trost@cookcountyil.gov>,  Jeffrey.Pasqua@cookcountyil.gov, 
Jennifer  Nowaczyk  (Sheriff)  <Jennifer.Nowaczyk@cookcountyil.gov>,  Jerome 
Ryan  (Sheriff)  <Jerome.Ryan@cookcountyil.gov>,  Jershawn  Dubose  (Sheriff) 
<Jershawn.Dubose@cookcountyil.gov>,  Jessica  Gatti  (Sheriff) 
<Jessica.Gatti@cookcountyil.gov>,  Jessica  McCants  (Sheriff) 
<Jessica.McCants@cookcountyil.gov>,  Jessica  Thomas  (Sheriff) 
<Jessica.Thomas@cookcountyil.gov>,  Jimeal  Haddad  (Sheriff) 
<Jimeal.Haddad@cookcountyil.gov>,  Jimmy  Olle  (Sheriff) 
<Jimmy.Olle@cookcountyil.gov>,  Joanna  Ryan  (Sheriff) 
<Joanna.Ryan@cookcountyil.gov>,  Joe  Dugandzic  (Sheriff) 
<Joe.Dugandzic@cookcountyil.gov>,  John  Aguilera  (Sheriff) 
<John.Aguilera2@cookcountyil.gov>,  John  Barloga  (Sheriff) 
<John.Barloga@cookcountyil.gov>,  John  Bennett  (Sheriff) 
<John.Bennett@cookcountyil.gov>,  John  Blair  (Sheriff) 
<John.Blair@cookcountyil.gov>,  John  Braun  (Sheriff) 
<John.Braun@cookcountyil.gov>,  John  Dziedzic  (Sheriff) 
<John.Dziedzic@cookcountyil.gov>,  John  Files  (Sheriff) 
<John.Files@cookcountyil.gov>,  John  Gallagher  (Sheriff) 
<John.Gallagher@cookcountyil.gov>,  John  Konrad  (Sheriff) 
<John.Konrad@cookcountyil.gov>,  John  Kowalczyk  (Sheriff) 
<John.Kowalczyk@cookcountyil.gov>,  John  Kruswicki  (Sheriff) 
<John.Kruswicki@cookcountyil.gov>,  John  Merola  (Sheriff) 
<John.Merola@cookcountyil.gov>,  John  Nawara  (Sheriff) 
<John.Nawara@cookcountyil.gov>,  John  O'Farrell  (Sheriff) 
<John.Ofarrell@cookcountyil.gov>,  John  Pradun  (Sheriff) 
<John.Pradun@cookcountyil.gov>,  John  Riggio  (Sheriff) 
<John.Riggio@cookcountyil.gov>,  John  Simone  (Sheriff) 
<John.Simone@cookcountyil.gov>,  John  Slepski  (Sheriff) 
<John.Slepski@cookcountyil.gov>,  John  Steed  (Sheriff) 
<John.Steed@cookcountyil.gov>,  John  Sullivan  (Sheriff) 
<John.Sullivan2@cookcountyil.gov>,  John  Vega  (Sheriff) 
<John.Vega@cookcountyil.gov>,  Johnny  Cantu  (Sheriff) 
<Johnny.Cantu@cookcountyil.gov>,  Jonathan  Janulis  (Sheriff) 


<Jonathan.Janulis@cookcountyil.gov>,  Jonathan  Pilli  (Sheriff) 
<Jonathan.Pilli@cookcountyil.gov>,  Jonathan.Mobley@cookcountyil.gov, 
Jordan  Green  (Sheriff)  <Jordan.Green@cookcountyil.gov>,  Jorge  Gali  (Sheriff) 
<Jorge.Gali@cookcountyil.gov>,  Jorge  Mayen  (Sheriff) 
<Jorge.Mayen@cookcountyil.gov>,  Jose  Delvalle  (Sheriff) 
<Jose.Delvalle@cookcountyil.gov>,  Jose  Madrid  (Sheriff) 
<Jose.Madrid@cookcountyil.gov>,  Jose  Martinez  (Sheriff) 
<Jose.Martinez2@cookcountyil.gov>,  Jose  Reyna  (Sheriff) 
<Jose.Reyna@cookcountyil.gov>,  Jose  Rodriguez  (Sheriff) 
<Jose.Rodriguez4@cookcountyil.gov>,  Jose  Rosario  (Sheriff) 
<Jose.Rosario@cookcountyil.gov>,  Joseph  Alva  (Sheriff) 
<Joseph.Alva@cookcountyil.gov>,  Joseph  Burdi  (Sheriff) 
<Joseph.Burdi@cookcountyil.gov>,  Joseph  Calderone  (Sheriff) 
<Joseph.Calderone@cookcountyil.gov>,  Joseph  Chirillo  (Sheriff) 
<Joseph.Chirillo@cookcountyil.gov>,  Joseph  Dale  (Sheriff) 
<Joseph.Dale@cookcountyil.gov>,  Joseph  Gudella  (Sheriff) 
<Joseph.Gudella@cookcountyil.gov>,  Joseph  Maselko  (Sheriff) 
<Joseph.Maselko@cookcountyil.gov>,  Joseph  McGough  (Sheriff) 
<Joseph.McGough@cookcountyil.gov>,  Joseph  Nicholas  (Sheriff) 
<Joseph.Nicholas@cookcountyil.gov>,  Joseph  Park  (Sheriff) 
<Joseph.Park@cookcountyil.gov>,  Joseph  Phillips  (Sheriff) 
<Joseph.Phillips@cookcountyil.gov>,  Joseph  Piersanti  (Sheriff) 
<Joseph.Piersanti@cookcountyil.gov>,  Joseph  Rosenau  (Sheriff) 
<Joseph.Rosenau@cookcountyil.gov>,  Joseph  Scofield  (Sheriff) 
<Joseph.Scofield@cookcountyil.gov>,  Joseph  Smith  (Sheriff) 
<Joseph.Smith@cookcountyil.gov>,  Joseph  Vertucci  (Sheriff) 
<Joseph.Vertucci@cookcountyil.gov>,  Joshua  Johnson  (Sheriff) 
<Joshua.Johnson@cookcountyil.gov>,  Joyce  Lowery  (Sheriff) 
<Joyce.Lowery@cookcountyil.gov>,  Juan  Arellano  (Sheriff) 
<Juan.Arellano@cookcountyil.gov>,  Juan  Claudio  (Sheriff) 
<Juan.Claudio@cookcountyil.gov>,  Juan  Irizarry  (Sheriff) 
<Juan.lrizarry@cookcountyil.gov>,  Juan  Mata  (Sheriff) 
<Juan.Mata@cookcountyil.gov>,  Juan  Tapia  (Sheriff) 
<Juan.Tapia@cookcountyil.gov>,  Juan  Velez  (Sheriff) 
<Juan.Velez@cookcountyil.gov>,  Juanita  Blaino  (Sheriff) 
<Juanita.Blaino@cookcountyil.gov>,  Judith  Powe  (Sheriff) 
<Judith.Powe@cookcountyil.gov>,  Julie  Duffy  (Sheriff) 
<Julie.Duffy@cookcountyil.gov>,  Julie  Spencer  (Sheriff) 
<Julie.Spencer@cookcountyil.gov>,  Justin  Jones  (Sheriff) 
<Justin.Jones@cookcountyil.gov>,  Kanisha  Rodriguez  (Sheriff) 
<Kanisha.Rodriguez@cookcountyil.gov>,  Karen  Amegatcher  (Sheriff) 
<Karen.Amegatcher@cookcountyil.gov>,  Karl  Thomas  (Sheriff) 
<Karl.Thomas@cookcountyil.gov>,  Karol  Suchocki  (Sheriff) 
<Karol.Suchocki@cookcountyil.gov>,  Katarzyna  Wells  (Sheriff) 
<Katarzyna.Wells@cookcountyil.gov>,  Katherine  Walsh  (Sheriff) 
<Katherine.Walsh@cookcountyil.gov>,  Kathleen  Efta  (Sheriff) 
<Kathleen.Efta@cookcountyil.gov>,  Keena  Bradley  (Sheriff) 
<Keena.Bradley@cookcountyil.gov>,  Keith  Garner  (Sheriff) 
<Keith.Garner@cookcountyil.gov>,  Keith  Gray  (Sheriff) 
<Keith.Gray@cookcountyil.gov>,  Keith  Me  Carter  (Sheriff) 
<Keith.McCarter@cookcountyil.gov>,  Keith  Morrison  (Sheriff) 
<Keith.Morrison@cookcountyil.gov>,  Kelley  Kleist  (Sheriff) 
<Kelley.Kleist@cookcountyil.gov>,  Kelly  Rohe  (Sheriff) 
<Kelly.Rohe2@cookcountyil.gov>,  Kelly  Stott  (Sheriff) 
<Kelly.Stott@cookcountyil.gov>,  Kelly  Sweeney  (Sheriff) 
<Kelly.Sweeney@cookcountyil.gov>,  Kelvin  Blanchard  (Sheriff) 
<Kelvin.Blanchard@cookcountyil.gov>,  Kendall  Evans  (Sheriff) 
<Kendall.Evans@cookcountyil.gov>,  Kenneth  Vargas  (Sheriff) 
<Kenneth.Vargas@cookcountyil.gov>,  Keri  Baker  (Sheriff) 
<Keri.Baker@cookcountyil.gov>,  Kevin  Badon  (Sheriff) 
<Kevin.Badon@cookcountyil.gov>,  Kevin  Boens  (Sheriff) 
<Kevin.Boens@cookcountyil.gov>,  Kevin  Christofidis  (Sheriff) 
<Kevin.Christofidis@cookcountyil.gov>,  Kevin  Cooper  (Sheriff) 


<Kevin.Cooper@cookcountyil.gov>,  Kevin  Ellis  (Sheriff) 

<Kevin.Ellis@cookcountyil.gov>,  Kevin  Enyart  (Sheriff) 

<Kevin.Enyart@cookcountyil.gov>,  Kevin  Farrell  (Sheriff) 
<Kevin.Farrell@cookcountyil.gov>,  Kevin  Graff  (Sheriff) 

<Kevin.Graff@cookcountyil.gov>,  Kevin  Kelly  (Sheriff) 

<Kevin.Kelly@cookcountyil.gov>,  Kevin  O'Donnell  (Sheriff) 
<Kevin.Odonnell@cookcountyil.gov>,  Kevin  O'Reilly  (Sheriff) 
<Kevin.Oreilly@cookcountyil.gov>,  Kevin  Ruel  (Sheriff) 

<Kevin.Ruel@cookcountyil.gov>,  Kevin  Suchocki  (Sheriff) 
<Kevin.Suchocki@cookcountyil.gov>,  Kevin  Tomkins  (Sheriff) 
<Kevin.Tomkins@cookcountyil.gov>,  Kevin  Walsh  (Sheriff) 
<Kevin.Walsh@cookcountyil.gov>,  Khaleelah  Sneed  (Sheriff) 
<Khaleelah.Sneed@cookcountyil.gov>,  Kiersten  Kendall  (Sheriff) 
<Kiersten.Kendall@cookcountyil.gov>,  Kimberley  Guerin  (Sheriff) 
<Kimberley.Guerin@cookcountyil.gov>,  Kimberly  Brown  (Sheriff) 
<Kimberly.Brown@cookcountyil.gov>,  Kimberly  Capelli  (Sheriff) 
<Kimberly.Capelli@cookcountyil.gov>,  Kimberly  Germain  (Sheriff) 
<Kimberly.Germain@cookcountyil.gov>,  Kimberly  Gouwens  (Sheriff) 
<Kimberly.Gouwens@cookcountyil.gov>,  Krzysztof  Piech  (Sheriff) 
<Krzysztof.Piech@cookcountyil.gov>,  Krzysztof  Wantuch  (Sheriff) 
<Krzysztof.Wantuch@cookcountyil.gov>,  Kyle  Kelley  (Sheriff) 
<Kyle.Kelley@cookcountyil.gov>,  Kyle  Sellers  (Sheriff) 

<Kyle.Sellers2@cookcountyil.gov>,  Lakesha  Palomino  (Sheriff) 
<Lakesha.Palomino@cookcountyil.gov>,  Lasean  Miller  (Sheriff) 
<LaSean.Miller@cookcountyil.gov>,  Lashawn  Simmons  (Sheriff) 
<Lashawn.Simmons@cookcountyil.gov>,  Latonya  Boyette  (Sheriff) 
<Latonya.Boyette@cookcountyil.gov>,  Latrice  Rattler  (Sheriff) 
<Latrice.Rattler@cookcountyil.gov>,  Latrice  Thomas  (Sheriff) 
<Latrice.Thomas@cookcountyil.gov>,  Laura  Becker  (Sheriff) 
<Laura.Becker@cookcountyil.gov>,  Lauren  Langland  (Sheriff) 
<Lauren.Langland@cookcountyil.gov>,  Lawrence  O'Rourke  (Sheriff) 
<lawrence.orourke@cookcountyil.gov>,  Leanna  Carlson  (Sheriff) 
<Leanna.Carlson@cookcountyil.gov>,  Leanne  Hovey  (Sheriff) 
<Leanne.Hovey@cookcountyil.gov>,  Leone  Ugarte  Avila  (Sheriff) 
<Leone.UgarteAvila@cookcountyil.gov>,  Leslie  Pratts  (Sheriff) 
<Leslie.Pratts@cookcountyil.gov>,  Lester  Rodgers  (Sheriff) 
<Lester.Rodgers@cookcountyil.gov>,  Levita  Perkins  (Sheriff) 
<Levita.Perkins@cookcountyil.gov>,  Lina  Rackauskaite  (Sheriff) 
<Lina.Rackauskaite@cookcountyil.gov>,  Linda  Olinski  (Sheriff) 
<Linda.Olinski@cookcountyil.gov>,  Lisa  Farinella  (Sheriff) 
<Lisa.Farinella@cookcountyil.gov>,  Lisa  Garza  (Sheriff) 

<Lisa.Garza@cookcountyil.gov>,  Lissette  Rivera  (Sheriff) 
<Lissette.Rivera@cookcountyil.gov>,  L'mekka  Edwards  (Sheriff) 
<lmekka.edwards@cookcountyil.gov>,  Lori  Hernandez  (Sheriff) 
<Lori.Hernandez@cookcountyil.gov>,  Louie  Goros  (Sheriff) 
<Louie.Goros@cookcountyil.gov>,  Luis  Blanco  (Sheriff) 

<Luis.Blanco@cookcountyil.gov>,  Luis  Domenech  (Sheriff) 
<Luis.Domenech@cookcountyil.gov>,  Luis  Santoyo  (Sheriff) 
<Luis.Santoyo@cookcountyil.gov>,  Luz  Evelia  Serrano  (Sheriff) 
<LuzEvelia.Serrano@cookcountyil.gov>,  Patrick  Dwyer  (Sheriff) 
<Patrick.Dwyer@cookcountyil.gov> 

Sent:  June  30,  2020  8:07:20  AM  CDT 

Received:  June  30,  2020  8:07:23  AM  CDT 

Attachments:  (U--FOUO)  MB  -  Criminal  Hackers  Target  US  Law  Enforcement  Data 

06262020.pdf 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated 
June  29,  2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a 
hack-and-leak  operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support 
of  or  in  response  to  nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years 
of  data  from  200  police  departments,  fusion  centers,  and  other  law  enforcement  training  and  support 


resources  around  the  globe,  according  to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack- 
and-leak  activity  against  the  Russian  Government. 


If  you  no  longer  wish  to  be  on  this  distribution  list,  please  send  an  email  to  ccso.intel@cookcountyil.gov  to  discontinue  receiving 
these  emails.  If  you  would  like  any  member  under  your  command  to  receive  these  emails,  please  send  an  email  to 
ccso.intel@cookcormtyil.gov  and  include  their  name,  title  and  email  address  in  the  body  of  the  request. 


Cook  County  Sheriffs  Office 
Strategic  Operations  Center 
3026  S.  California  Avenue 
Building  5,  2nd  Floor 
Chicago,  IL.  60608 
Office:  773-674-2694  or  8477 
Fax:  773-674-4797 


THIS  IS  A  CONFIDENTIAL  LAW  ENFORCEMENT  COMMUNICATION.  The  contents  of  this  e-mail  message  and  any 
attachments  are  intended  solely  for  the  addressee(s)  named  in  this  message.  This  communication  is  intended  to  be  and  to  remain 
confidential.  If  you  are  not  the  intended  recipient  of  this  message,  or  if  this  message  has  been  addressed  to  you  in  error,  please 
immediately  alert  the  sender  by  reply  e-mail  and  then  delete  this  message  and  its  attachments.  Do  not  deliver,  distribute,  transmit 
or  copy  this  message  and/or  any  attachments  and  if  you  are  not  the  intended  recipient,  do  not  disclose  the  contents  or  take  any 
action  relative  to  the  information  contained  in  this  communication  and/or  attachments.  This  e-mail  and  any  attached  documents 
may  contain  For  Official  Use  Only  and/or  Law  Enforcement  Sensitive  material  and  should  not  be  disseminated  outside  of  official 
law  enforcement  channels.  The  information  contained  in  this  message  as  well  as  any  attachments  shall  not  be  released  to  the 
media  or  the  general  public. 


FW:  Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement 
Data 


Keith  Morrison  (Sheriff)  <Keith.Morrison@cookcountyil.gov> 
Christopher  Moore  (Sheriff)  <Christopher.Moore@cookcountyil.gov> 
June  30,  2020  8:07:29  AM  CDT 
June  30,  2020  8:07:30  AM  CDT 

(U--FOUO)  I  IB  -  Criminal  Hackers  Target  US  Law  Enforcement  Data 
06262020.pdf 


From: 

To: 

Sent: 

Received: 

Attachments: 


From:  CCSO  Intel  (Sheriff) 

Sent:  Tuesday,  June  30,  2020  8:07:20  AM  (UTC-06:00)  Central  Time  (US  &  Canada) 

Subject:  Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated 
June  29,  2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a 
hack-and-leak  operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support 
of  or  in  response  to  nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years 
of  data  from  200  police  departments,  fusion  centers,  and  other  law  enforcement  training  and  support 
resources  around  the  globe,  according  to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack- 
and-leak  activity  against  the  Russian  Government. 

If  you  no  longer  wish  to  be  on  this  distribution  list,  please  send  an  email  to  ccso.intel@cookcountyil.gov  to  discontinue  receiving 
these  emails.  If  you  would  like  any  member  under  your  command  to  receive  these  emails,  please  send  an  email  to 
ccso.intel@cookcountyil.gov  and  include  their  name,  title  and  email  address  in  the  body  of  the  request. 


Cook  County  Sheriffs  Office 
Strategic  Operations  Center 
3026  S.  California  Avenue 
Building  5,  2nd  Floor 
Chicago,  IL.  60608 
Office:  773-674-2694  or  8477 
Fax:  773-674-4797 


THIS  IS  A  CONFIDENTIAL  LAW  ENFORCEMENT  COMMUNICATION.  The  contents  of  this  e-mail  message  and  any 
attachments  are  intended  solely  for  the  addressee(s)  named  in  this  message.  This  communication  is  intended  to  be  and  to  remain 
confidential.  If  you  are  not  the  intended  recipient  of  this  message,  or  if  this  message  has  been  addressed  to  you  in  error,  please 
immediately  alert  the  sender  by  reply  e-mail  and  then  delete  this  message  and  its  attachments.  Do  not  deliver,  distribute,  transmit 
or  copy  this  message  and/or  any  attachments  and  if  you  are  not  the  intended  recipient,  do  not  disclose  the  contents  or  take  any 
action  relative  to  the  information  contained  in  this  communication  and/or  attachments.  This  e-mail  and  any  attached  documents 
may  contain  For  Official  Use  Only  and/or  Law  Enforcement  Sensitive  material  and  should  not  be  disseminated  outside  of  official 
law  enforcement  channels.  The  information  contained  in  this  message  as  well  as  any  attachments  shall  not  be  released  to  the 
media  or  the  general  public. 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 


To:  Yolanda  Collins-Watson  (Sheriff) 

Sent:  June  30,  2020  8:07:45  AM  CDT 

Received:  June  30,  2020  8:07:51  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Todd  Rohl  (Sheriff) 

Sent:  June  30,  2020  8:07:45  AM  CDT 

Received:  June  30,  2020  8:07:51  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Walter  Klinger  (Sheriff) 

Sent:  June  30,  2020  8:07:45  AM  CDT 

Received:  June  30,  2020  8:07:51  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Patricia  Montgomery-Echols  (Sheriff) 

Sent:  June  30,  2020  8:07:45  AM  CDT 

Received:  June  30,  2020  8:07:51  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Michael  Goldsmith  (Sheriff) 

Sent:  June  30,  2020  8:07:45  AM  CDT 

Received:  June  30,  2020  8:07:51  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Nathan  Camer  (Sheriff) 

Sent:  June  30,  2020  8:07:45  AM  CDT 

Received:  June  30,  2020  8:07:51  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Timothy  O'Donnell  (Sheriff) 

Sent:  June  30,  2020  8:07:45  AM  CDT 

Received:  June  30,  2020  8:07:51  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Tarra  Daniels-Davis  (Sheriff) 

Sent:  June  30,  2020  8:07:45  AM  CDT 

Received:  June  30,  2020  8:07:51  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Randall  Pochie  (Sheriff) 

Sent:  June  30,  2020  8:07:45  AM  CDT 

Received:  June  30,  2020  8:07:51  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Patrick  Dwyer  (Sheriff) 

Sent:  June  30,  2020  8:07:45  AM  CDT 

Received:  June  30,  2020  8:07:51  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Rebecca  Dejesus  (Sheriff) 

Sent:  June  30,  2020  8:07:45  AM  CDT 

Received:  June  30,  2020  8:07:51  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Matthew  Goral  (Sheriff) 

Sent:  June  30,  2020  8:07:45  AM  CDT 

Received:  June  30,  2020  8:07:51  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Martin  Bennett  (Sheriff) 

Sent:  June  30,  2020  8:07:45  AM  CDT 

Received:  June  30,  2020  8:07:51  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Stavone  McHerron  (Sheriff) 

Sent:  June  30,  2020  8:07:45  AM  CDT 

Received:  June  30,  2020  8:07:51  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

To:  Richard  O'Brien  (Sheriff) 

Sent:  June  30,  2020  8:07:45  AM  CDT 

Received:  June  30,  2020  8:07:50  AM  CDT 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

From:  CCSO  Intel  (Sheriff)  <CCSO.INTEL@cookcountyil.gov> 

Bcc:  Leo  Schmitz  (Sheriff)  <Leo.Schmitz@cookcountyil.gov>,  Marcin  Szczerbiak 

(Sheriff)  <Marcin.Szczerbiak@cookcountyil.gov>,  Marcus  Bradfield  (Sheriff) 
<Marcus.Bradfield@cookcountyil.gov>,  Margie  Sullivan  (Sheriff) 
<Margie.Sullivan@cookcountyil.gov>,  Marguerite  McCluskey  (Sheriff) 
<Marguerite.McCluskey@cookcountyil.gov>,  Maria  Lopez  (Sheriff) 
<Maria.Lopez@cookcountyil.gov>,  Marie  Jeffries  (Sheriff) 
<Marie.Jeffries@cookcountyil.gov>,  Mario  Ponce  (Sheriff) 
<Mario.Ponce@cookcountyil.gov>,  Marissa  Sanchez  (Sheriff) 
<Marissa.Sanchez@cookcountyil.gov>,  Marissa  SanchezKrug  (Sheriff) 
<Marissa.SanchezKrug@cookcountyil.gov>,  Mark  Mendoza  (Sheriff) 
<Mark.Mendoza@cookcountyil.gov>,  Mark  Smith  (Sheriff) 
<Mark.Smith@cookcountyil.gov>,  Marlon  Parks  (Sheriff) 
<Marlon.Parks@cookcountyil.gov>,  Marshan  Johnson  (Sheriff) 
<Marshan.Johnson@cookcountyil.gov>,  Martin  Bennett  (Sheriff) 
<Martin.Bennett@cookcountyil.gov>,  Martin  Hart  (Sheriff) 
<Martin.Hart@cookcountyil.gov>,  Martin  Juppe  (Sheriff) 
<Martin.Juppe@cookcountyil.gov>,  Martin  Lukasik  (Sheriff) 
<Martin.Lukasik@cookcountyil.gov>,  Martin  Webster  (Sheriff) 
<Martin.Webster@cookcountyil.gov>,  Mary  Przybylski  (Sheriff) 
<Mary.Przybylski@cookcountyil.gov>,  Mary.Tamme@cookcountyil.gov, 

Matthew  Brown  (Sheriff)  <Matthew.Brown@cookcountyil.gov>,  Matthew 
Carlson  (Sheriff)  <Matthew.Carlson@cookcountyil.gov>,  Matthew  Coffey 
(Sheriff)  <Matthew.Coffey@cookcountyil.gov>,  Matthew  Gena  (Sheriff) 
<Matthew.Gena@cookcountyil.gov>,  Matthew  Goral  (Sheriff) 
<Matthew.Goral@cookcountyil.gov>,  Matthew  Rafferty  (Sheriff) 
<Matthew.Rafferty@cookcountyil.gov>,  Matthew  Walsh  (Sheriff) 
<Matthew.Walsh@cookcountyil.gov>,  Matthias  Vlahos  (Sheriff) 
<Matthias.Vlahos@cookcountyil.gov>,  Maureen  Donohoe  (Sheriff) 
<Maureen.Donohoe@cookcountyil.gov>,  Maurice  Ashford  (Sheriff) 
<Maurice.Ashford@cookcountyil.gov>,  Maurice  Cernick  (Sheriff) 
<Maurice.Cernick@cookcountyil.gov>,  Megan  Kinsella  (Sheriff) 
<Megan.Kinsella@cookcountyil.gov>,  Michael  Anton  (Sheriff) 
<Michael.Anton@cookcountyil.gov>,  Michael  Callahan  (Sheriff) 
<Michael.Callahan1@cookcountyil.gov>,  Michael  Cokeley  (Sheriff) 
<Michael.Cokeley@cookcountyil.gov>,  Michael  Contreras  (Sheriff) 
<Michael.Contreras@cookcountyil.gov>,  Michael  Dwyer  (Sheriff) 
<Michael.Dwyer@cookcountyil.gov>,  Michael  Elsen  (Sheriff) 
<Michael.Elsen@cookcountyil.gov>,  Michael  Fonseca  (Sheriff) 
<Michael.Fonseca@cookcountyil.gov>,  Michael  Gleason  (Sheriff) 
<Michael.Gleason@cookcountyil.gov>,  Michael  Gniedziejko  (Sheriff) 
<Michael.Gniedziejko@cookcountyil.gov>,  Michael  Goldsmith  (Sheriff) 
<Michael.Goldsmith@cookcountyil.gov>,  Michael  Gomez  (Sheriff) 
<Michael.Gomez@cookcountyil.gov>,  Michael  Healy  (Sheriff) 
<Michael.Healy@cookcountyil.gov>,  Michael  Holewinski  (Sheriff) 
<Michael.Holewinski@cookcountyil.gov>,  Michael  Juraszek  (Sheriff) 
<Michael.Juraszek@cookcountyil.gov>,  Michael  Kane  (Sheriff) 
<Michael.Kane@cookcountyil.gov>,  Michael  Kizaric  (Sheriff) 
<Michael.Kizaric@cookcountyil.gov>,  Michael  Knighton  (Sheriff) 
<Michael.Knighton@cookcountyil.gov>,  Michael  Kruzel  (Sheriff) 
<Michael.Kruzel@cookcountyil.gov>,  Michael  Lucente  (Sheriff) 
<Michael.Lucente@cookcountyil.gov>,  Michael  Mendez  (Sheriff) 
<Michael.Mendez@cookcountyil.gov>,  Michael  Murphy  (Sheriff) 
<Michael.Murphy2@cookcountyil.gov>,  Michael  Murphyl  (Sheriff) 
<Michael.Murphy@cookcountyil.gov>,  Michael  Parks  (Sheriff) 
<Michael.Parks@cookcountyil.gov>,  Michael  Quan  (Sheriff) 
<Michael.Quan@cookcountyil.gov>,  Michael  Raab  (Sheriff) 
<Michael.Raab@cookcountyil.gov>,  Michael  Rivers  (Sheriff) 
<Michael.Rivers@cookcountyil.gov>,  Michael  Schaffer  (Sheriff) 
<Michael.Schaffer@cookcountyil.gov>,  Michael  Sisco  (Sheriff) 


<Michael.Sisco@cookcountyil.gov>,  Michael  Storino  (Sheriff) 
<Michael.Storino@cookcountyil.gov>,  Michael  Ware  (Sheriff) 
<Michael.Ware2@cookcountyil.gov>,  Michael  Ware  (Sheriff) 
<Michael.Ware@cookcountyil.gov>,  Michelle  Allen  (Sheriff) 
<Michelle.Allen@cookcountyil.gov>,  Michelle  Dorn  (Sheriff) 
<Michelle.Dorn@cookcountyil.gov>,  Michelle  Jagielko  (Sheriff) 
<Michelle.Jagielko@cookcountyil.gov>,  Michelle  Kaechele  (Sheriff) 
<Michelle.Kaechele@cookcountyil.gov>,  Milan  Stojkovic  (Sheriff) 
<Milan.Stojkovic@cookcountyil.gov>,  Mildred  Valenzuela  (Sheriff) 
<Mildred.Valenzuela@cookcountyil.gov>,  Mirella  Delgado  (Sheriff) 
<Mirella.Delgado@cookcountyil.gov>,  Miriam  Bernal  (Sheriff) 
<Miriam.Bernal@cookcountyil.gov>,  Mizell  Walls  (Sheriff) 
<Mizell.Walls@cookcountyil.gov>,  Mohammed  Akhtar  (Sheriff) 
<Mohammed.Akhtar@cookcountyil.gov>,  Myron  Weres  (Sheriff) 
<Myron.Weres@cookcountyil.gov>,  Naima  Howard  (Sheriff) 
<Naima.Howard@cookcountyil.gov>,  Nancy  Pavelka  (Sheriff) 
<Nancy.Pavelka@cookcountyil.gov>,  Natasha  Alien-Victor  (Sheriff) 
<Natasha.Allen-Victor2@cookcountyil.gov>,  Natasha  Williams  (Sheriff) 
<Natasha.Williams@cookcountyil.gov>,  Nathan  Bowens  (Sheriff) 
<Nathan.Bowens@cookcountyil.gov>,  Nathan  Camer  (Sheriff) 
<Nathan.Camer@cookcountyil.gov>,  Nelson  Lewis  (Sheriff) 
<Nelson.Lewis@cookcountyil.gov>,  Nicholas  Bohlsen  (Sheriff) 
<Nicholas.Bohlsen@cookcountyil.gov>,  Nicholas  Trinidad  (Sheriff) 
<Nicholas.Trinidad@cookcountyil.gov>,  Nick  Karlos  (Sheriff) 
<Nick.Karlos@cookcountyil.gov>,  Nicole  Gordon  (Sheriff) 
<Nicole.Gordon@cookcountyil.gov>,  Nicole  Valerio  (Sheriff) 
<Nicole.Valerio@cookcountyil.gov>,  NikTrzinski  (Sheriff) 
<Nik.Trzinski@cookcountyil.gov>,  Nikolas  Hadjian  (Sheriff) 
<Nikolas.Hadjian@cookcountyil.gov>,  Noel  Perez  (Sheriff) 
<Noel.Perez@cookcountyil.gov>,  Pablo  Trujillo  (Sheriff) 
<Pablo.Trujillo@cookcountyil.gov>,  Pamela  Harrington  (Sheriff) 
<Pamela.Harrington@cookcountyil.gov>,  Pamela  Williams  (Sheriff) 
<Pamela.Williams@cookcountyil.gov>,  Pascal  Waller  (Sheriff) 
<Pascal.Waller@cookcountyil.gov>,  Patricia  Duffy  (Sheriff) 
<Patricia.Duffy@cookcountyil.gov>,  Patricia  Montgomery-Echols  (Sheriff) 
<Patricia. Montgomery-echols@cookcountyil.gov>,  Patrick  Barbella  (Sheriff) 
<Patrick.Barbella@cookcountyil.gov>,  Patrick  Brosnan  (Sheriff) 
<Patrick.Brosnan@cookcountyil.gov>,  Patrick  Donovan  (Sheriff) 
<Patrick.Donovan@cookcountyil.gov>,  Patrick  Doyle  (Sheriff) 
<Patrick.Doyle@cookcountyil.gov>,  Patrick  Dwyer  (Sheriff) 
<Patrick.Dwyer@cookcountyil.gov>,  Patrick  Hurley  (Sheriff) 
<Patrick.Hurley@cookcountyil.gov>,  Patrick  Julian  (Sheriff) 
<Patrick.Julian@cookcountyil.gov>,  Patrick  Murray  (Sheriff) 
<Patrick.Murray@cookcountyil.gov>,  Patrina  McCoy  (Sheriff) 
<Patrina.Mccoy@cookcountyil.gov>,  Paul  Huss  (Sheriff) 
<Paul.Huss@cookcountyil.gov>,  Paul  Martinez  (Sheriff) 
<Paul.Martinez@cookcountyil.gov>,  Paul  Riley  (Sheriff) 
<Paul.Riley@cookcountyil.gov>,  Paulina  Gorzkowska  (Sheriff) 
<Paulina.Gorzkowska@cookcountyil.gov>,  Penny  Mateck-Greene  (Sheriff) 
<Penny.Mateck-Greene@cookcountyil.gov>,  Perry  Triveri  (Sheriff) 
<Perry.Triveri@cookcountyil.gov>,  Peter  Boubourekas  (Sheriff) 
<Peter.Boubourekas@cookcountyil.gov>,  Peter  Raines  (Sheriff) 
<Peter.Raines@cookcountyil.gov>,  Philip  Fraticola  (Sheriff) 
<Philip.Fraticola@cookcountyil.gov>,  Philip  Lapuma  (Sheriff) 
<Philip.Lapuma@cookcountyil.gov>,  Philip  Metcalf  (Sheriff) 
<Philip.Metcalf@cookcountyil.gov>,  Phillip  Mackey  (Sheriff) 
<Phillip.Mackey@cookcountyil.gov>,  Quiana  Washington  (Sheriff) 
<Quiana.Washington@cookcountyil.gov>,  Rachel  Koch  (Sheriff) 
<Rachel.Koch2@cookcountyil.gov>,  Rafael  Ruiz  (Sheriff) 
<Rafael.Ruiz@cookcountyil.gov>,  Ramon  Del  Valle  (Sheriff) 
<Ramon.Delvalle@cookcountyil.gov>,  Randa  Abuteen  (Sheriff) 
<Randa.Abuteen@cookcountyil.gov>,  Randall  Pochie  (Sheriff) 
<Randall.Pochie@cookcountyil.gov>,  Randall  Quill  (Sheriff) 


<Randall.Quill@cookcountyil.gov>,  Raul  Garcia  (Sheriff) 
<Raul.Garcia2@cookcountyil.gov>,  Raymond  Struck  (Sheriff) 
<Raymond.Struck@cookcountyil.gov>,  Rebecca  Cancellare  (Sheriff) 
<Rebecca.Cancellare@cookcountyil.gov>,  Rebecca  Coughlin  (Sheriff) 
<Rebecca.Coughlin@cookcountyil.gov>,  Rebecca  Dejesus  (Sheriff) 
<Rebecca.Dejesus@cookcountyil.gov>,  Rebecca  Llanes  (Sheriff) 
<Rebecca.Llanes@cookcountyil.gov>,  Renee  Richardson  (Sheriff) 
<Renee.Richardson@cookcountyil.gov>,  Renee  Smith  (Sheriff) 
<Renee.Smith@cookcountyil.gov>,  Rex  Knaperek  (Sheriff) 
<Rex.Knaperek@cookcountyil.gov>,  Ricardo  Hardy  (Sheriff) 
<Ricardo.Hardy@cookcountyil.gov>,  Ricardo  Ibarra  (Sheriff) 
<Ricardo.lbarra@cookcountyil.gov>,  Richard  Delavega  (Sheriff) 
<Richard.Delavega@cookcountyil.gov>,  Richard  Garcial  (Sheriff) 
<Richard.Garcia2@cookcountyil.gov>,  Richard  Jurgens  (Sheriff) 
<Richard.Jurgens@cookcountyil.gov>,  Richard  Liboy  (Sheriff) 
<Richard.Liboy@cookcountyil.gov>,  Richard  O'Brienl  (Sheriff) 
<Richard.O'brien2@cookcountyil.gov>,  Richard  Petersen  (Sheriff) 
<Richard.Petersen@cookcountyil.gov>,  Richard  Urso  (Sheriff) 
<Richard.Urso@cookcountyil.gov>,  Richard  Velasquez  (Sheriff) 
<Richard.Velasquez@cookcountyil.gov>,  Rikki  Johnson  (Sheriff) 
<Rikki.Johnson@cookcountyil.gov>,  Rita  Mendez  (Sheriff) 
<Rita.Mendez@cookcountyil.gov>,  Robert  Almeida  (Sheriff) 
<Robert.Almeida@cookcountyil.gov>,  Robert  Bonakowski  (Sheriff) 
<Robert.Bonakowski@cookcountyil.gov>,  Robert  Cassidy  (Sheriff) 
<Robert.Cassidy@cookcountyil.gov>,  Robert  Devogelear  (Sheriff) 
<Robert.Devogelear@cookcountyil.gov>,  Robert  Gassmann  (Sheriff) 
<Robert.Gassmann@cookcountyil.gov>,  Robert  Hausherr  (Sheriff) 
<Robert.Hausherr@cookcountyil.gov>,  Robert  Lobacz  (Sheriff) 
<Robert.Lobacz@cookcountyil.gov>,  Robert  Mousel  (Sheriff) 
<Robert.Mousel@cookcountyil.gov>,  Robert  O'Neill  (Sheriff) 
<Robert.O'Neill@cookcountyil.gov>,  Robert  Ortiz  (Sheriff) 
<Robert.Ortiz@cookcountyil.gov>,  Robert  Ruminski  (Sheriff) 
<Robert.Ruminski@cookcountyil.gov>,  Robert  Ryjewski  (Sheriff) 
<Robert.Ryjewski@cookcountyil.gov>,  Robert  Waller  (Sheriff) 
<Robert.Waller@cookcountyil.gov>,  Robert  Zivalich  (Sheriff) 
<Robert.Zivalich@cookcountyil.gov>,  Rochelle  Parker  (Sheriff) 
<Rochelle.Parker@cookcountyil.gov>,  Roderick  Kirkwood  (Sheriff) 
<Roderick.Kirkwood@cookcountyil.gov>,  Roderick  Pierce  (Sheriff) 
<Roderick.Pierce@cookcountyil.gov>,  Roger  Comer  (Sheriff) 
<Roger.Comer@cookcountyil.gov>,  Roger  Guerra  (Sheriff) 
<Roger.Guerra@cookcountyil.gov>,  Ronald  Prohaska  (Sheriff) 
<Ronald.Prohaska@cookcountyil.gov>,  Ronald  Sachtleben  (Sheriff) 
<Ronald.Sachtleben@cookcountyil.gov>,  Ronald  Szura  (Sheriff) 
<Ronald.Szura@cookcountyil.gov>,  Roy  Jones  (Sheriff) 
<Roy.Jones@cookcountyil.gov>,  Ruben  Rangel  (Sheriff) 
<Ruben.Rangel@cookcountyil.gov>,  Ruben  Salazar  (Sheriff) 
<Ruben.Salazar@cookcountyil.gov>,  Ruth  Mendez  (Sheriff) 
<Ruth.Mendez@cookcountyil.gov>,  Ryan  George  (Sheriff) 
<Ryan.George@cookcountyil.gov>,  Ryan  Huber  (Sheriff) 
<Ryan.Huber@cookcountyil.gov>,  Ryan  Killacky  (Sheriff) 
<Ryan.Killacky@cookcountyil.gov>,  Sajid  Haidari  (Sheriff) 
<Sajid.Haidari@cookcountyil.gov>,  Salvatore  Marra  (Sheriff) 
<Salvatore.Marra@cookcountyil.gov>,  Samina  Alva  (Sheriff) 
<Samina.Alva@cookcountyil.gov>,  Samina  Bonilla  (Sheriff) 
<Samina.Bonilla@cookcountyil.gov>,  Samuel  Cory  (Sheriff) 
<Samuel.Cory@cookcountyil.gov>,  Samuel  Senerchia  (Sheriff) 
<Samuel.Senerchia@cookcountyil.gov>,  Samuel  Suffern  (Sheriff) 
<Samuel.Suffern@cookcountyil.gov>,  Sandra  Crespo  Hernandez  (Sheriff) 
<Sandra.CrespoHernandez@cookcountyil.gov>,  Sang  Yi  (Sheriff) 
<Sang.Yi@cookcountyil.gov>,  Santiono  Dyer  (Sheriff) 
<Santiono.Dyer@cookcountyil.gov>,  Santo  Duffy  (Sheriff) 
<Santo.Duffy@cookcountyil.gov>,  Scott  Giertuga  (Sheriff) 
<Scott.Giertuga@cookcountyil.gov>,  Scott  Gordon  (Sheriff) 


<Scott.Gordon@cookcountyil.gov>,  Scott  Lefko  (Sheriff) 
<Scott.Lefko@cookcountyil.gov>,  Sean  Gleason  (Sheriff) 
<Sean.Gleason@cookcountyil.gov>,  Sean  Kelly  (Sheriff) 
<Sean.Kelly2@cookcountyil.gov>,  Sean  Murphy  (Sheriff) 
<Sean.Murphy@cookcountyil.gov>,  Sebastian  Golik  (Sheriff) 
<Sebastian.Golik@cookcountyil.gov>,  Servando  Velez  (Sheriff) 
<Servando.Velez@cookcountyil.gov>,  Sharon  Ustaszewski  (Sheriff) 
<Sharon.Ustaszewski@cookcountyil.gov>,  Shaunna  Rozhon  (Sheriff) 
<Shaunna.Rozhon@cookcountyil.gov>,  Shawn  Knapp  (Sheriff) 
<Shawn.Knapp@cookcountyil.gov>,  Shawn  Murphy  (Sheriff) 
<Shawn.Murphy@cookcountyil.gov>,  Shelly  Hendricks  (Sheriff) 
<Shelly. Hendricks@cookcountyil.gov>,  Shenita  Thomas  (Sheriff) 
<Shenita.Thomas@cookcountyil.gov>,  Sheree  Clark  (Sheriff) 
<Sheree.Clark@cookcountyil.gov>,  Shereen  Gamble  (Sheriff) 
<Shereen.Gamble1@cookcountyil.gov>,  Sheri  Holler  (Sheriff) 
<Sheri.Holler@cookcountyil.gov>,  Sherod  Craig  (Sheriff) 
<Sherod.Craig@cookcountyil.gov>,  Sheryl  Collins  (Sheriff) 
<Sheryl.Collins@cookcountyil.gov>,  Shirley  McGreal  (Sheriff) 
<Shirley.Mcgreal@cookcountyil.gov>,  Sonya  Delove  (Sheriff) 
<Sonya.DeLove@cookcountyil.gov>,  Stacey  Me  Queary  (Sheriff) 
<Stacey.Mcqueary@cookcountyil.gov>,  Stavone  McHerron  (Sheriff) 
<Stavone.Mcherron@cookcountyil.gov>,  Stephen  Moody  (Sheriff) 
<Stephen.Moody@cookcountyil.gov>,  Steven  Bialczak  (Sheriff) 
<Steven.Bialczak@cookcountyil.gov>,  Steven  Blazina  (Sheriff) 
<Steven.Blazina@cookcountyil.gov>,  Steven  Martino  (Sheriff) 
<Steven.Martino@cookcountyil.gov>,  Steven  Williams  (Sheriff) 
<Steven.Williams@cookcountyil.gov>,  Steven  Zepeda  (Sheriff) 
<Steven.Zepeda@cookcountyil.gov>,  Susan  Collum  (Sheriff) 
<Susan.Collum@cookcountyil.gov>,  Susano  Viramontes  (Sheriff) 
<Susano.Viramontes@cookcountyil.gov>,  Tamara  Levickas  (Sheriff) 
<Tamara.Levickas@cookcountyil.gov>,  Tamera  Jones  (Sheriff) 
<Tamera.Jones@cookcountyil.gov>,  Tanda  Adams  (Sheriff) 
<Tanda.Adams@cookcountyil.gov>,  Tangenise  Porter  (Sheriff) 
<Tangenise.Porter@cookcountyil.gov>,  Tarra  Daniels-Davis  (Sheriff) 
<Tarra.Daniels-Davis@cookcountyil.gov>,  Taylor  Boldt  (Sheriff) 
<Taylor.Boldt@cookcountyil.gov>,  Ted  Sakelaris  (Sheriff) 
<Ted.Sakelaris@cookcountyil.gov>,  Teresa  Ruiz  (Sheriff) 
<Teresa.Ruiz@cookcountyil.gov>,  Teresa  Serna  (Sheriff) 
<Teresa.Serna@cookcountyil.gov>,  Terese  Cruz  (Sheriff) 
<Terese.Cruz@cookcountyil.gov>,  Terra  Martin  (Sheriff) 
<Terra.Martin@cookcountyil.gov>,  Terrell  Andrews  (Sheriff) 
<Terrell.Andrews@cookcountyil.gov>,  Terrence  Doran  (Sheriff) 
<Terrence.Doran@cookcountyil.gov>,  Terrence  O'Driscoll  (Sheriff) 
<Terrence.O'Driscoll@cookcountyil.gov>,  Terrence  Ross  (Sheriff) 
<Terrence.Ross@cookcountyil.gov>,  Terrence  Tabb  (Sheriff) 
<Terrence.Tabb@cookcountyil.gov>,  Terrence  Whittier  (Sheriff) 
<Terrence.Whittler@cookcountyil.gov>,  Theodore  Stajura  (Sheriff) 
<Theodore.Stajura@cookcountyil.gov>,  Theodore  Williams  (Sheriff) 
<Theodore.Williams@cookcountyil.gov>,  Theresa  Hermann  (Sheriff) 
<Theresa.Hermann@cookcountyil.gov>,  Theresa  Trinidad  (Sheriff) 
<Theresa.Trinidad@cookcountyil.gov>,  Thomas  Albright  (Sheriff) 
<Thomas.Albright@cookcountyil.gov>,  Thomas  Burke  (Sheriff) 
<Thomas.Burke@cookcountyil.gov>,  Thomas  Clemmons  (Sheriff) 
<Thomas. Clemmons@cookcountyil.gov>,  Thomas  Maciunas  (Sheriff) 
<Thomas.Maciunas@cookcountyil.gov>,  Thomas  Me  Inerney  (Sheriff) 
<Thomas.Mcinerney@cookcountyil.gov>,  Thomas  McQuaid  (Sheriff) 
<Thomas.Mcquaid@cookcountyil.gov>,  Thomas  Nortman  (Sheriff) 
<Thomas.Nortman@cookcountyil.gov>,  Thomas  Shader  (Sheriff) 
<Thomas.Shader@cookcountyil.gov>,  Thomas  Sinks  (Sheriff) 
<Thomas.Sinks@cookcountyil.gov>,  Tiffany  Nagel  (Sheriff) 
<Tiffany.Nagel2@cookcountyil.gov>,  Timothy  Bergel  (Sheriff) 
<Timothy.Bergel@cookcountyil.gov>,  Timothy  Hannigan  (Sheriff) 
<Timothy.Hannigan@cookcountyil.gov>,  Timothy  Me  Phillips  (Sheriff) 


<Timothy.Mcphillips@cookcountyil.gov>,  Timothy  Murray  (Sheriff) 
<Timothy.Murray@cookcountyil.gov>,  Timothy  O'Donnell  (Sheriff) 
<Timothy.O'donnell@cookcountyil.gov>,  Timothy  Popp  (Sheriff) 
<Timothy.Popp@cookcountyil.gov>,  Todd  Lukas  (Sheriff) 
<Todd.Lukas@cookcountyil.gov>,  Todd  Rohl  (Sheriff) 

<Todd.Rohl@cookcountyil.gov>,  Toia  Sappington  (Sheriff) 
<Toia.Sappington@cookcountyil.gov>,  Tomas  Perez  (Sheriff) 
<Tomas.Perez@cookcountyil.gov>,  Tomasz  Tustanowski  (Sheriff) 
<Tomasz.Tustanowski@cookcountyil.gov>,  Tommie  Hall  (Sheriff) 
<Tommie.Hall@cookcountyil.gov>,  Tommy  Koniewicz  (Sheriff) 
<Tommy.Koniewicz@cookcountyil.gov>,  Tony  Wasco  (Sheriff) 
<Tony.Wasco@cookcountyil.gov>,  Tracy  Clopton  (Sheriff) 
<Tracy.Clopton@cookcountyil.gov>,  Tracy  O'Donnell  (Sheriff) 
<Tracy.ODonnell@cookcountyil.gov>,  Troy  Smith  (Sheriff) 
<Troy.Smith@cookcountyil.gov>,  Valerie  Gorniak  (Sheriff) 
<Valerie.Gorniak@cookcountyil.gov>,  Vernon  Jackson  (Sheriff) 
<Vernon.Jackson@cookcountyil.gov>,  Veronica  Roman  (Sheriff) 
<Veronica.Roman@cookcountyil.gov>,  Victor  Marin  (Sheriff) 
<Victor.Marin@cookcountyil.gov>,  Victor  Siedleski  (Sheriff) 
<Victor.Siedleski@cookcountyil.gov>,  Victor  Van  Horn  (Sheriff) 
<Victor.Vanhorn@cookcountyil.gov>,  Viktor  Yatsyk  (Sheriff) 
<Viktor.Yatsyk@cookcountyil.gov>,  Vincent  Gamez  (Sheriff) 
<Vincent.Gamez@cookcountyil.gov>,  Vincent  Garrett  (Sheriff) 
<Vincent.Garrett@cookcountyil.gov>,  Vincent  Greene  (Sheriff) 
<Vincent.Greene@cookcountyil.gov>,  Walter  Klinger  (Sheriff) 
<Walter.Klinger@cookcountyil.gov>,  Wanda  Barnes  (Sheriff) 
<Wanda.Barnes@cookcountyil.gov>,  Wanda  Cintron  (Sheriff) 
<Wanda.Cintron@cookcountyil.gov>,  Wanda  Walker  (Sheriff) 
<Wanda.Walker@cookcountyil.gov>,  Warrick  Graham  (Sheriff) 
<Warrick.Graham3@cookcountyil.gov>,  Wilfrido  Trejo  (Sheriff) 
<Wilfrido.Trejo@cookcountyil.gov>,  William  De  La  Fuente  (Sheriff) 
<William.Delafuente@cookcountyil.gov>,  William  Evers  (Sheriff) 
<William.Evers@cookcountyil.gov>,  William  Hoefler  (Sheriff) 
<William.Hoefler@cookcountyil.gov>,  William  Jackson  (Sheriff) 
<William.Jackson1@cookcountyil.gov>,  William  Jones  (Sheriff) 
<William.Jones@cookcountyil.gov>,  William  Leen  (Sheriff) 
<William.Leen@cookcountyil.gov>,  William  Mak  (Sheriff) 
<William.Mak@cookcountyil.gov>,  William  Moran  (Sheriff) 
<William.Moran@cookcountyil.gov>,  William  O'Mary  (Sheriff) 
<William.O'Mary@cookcountyil.gov>,  William  Smith  (Sheriff) 
<William.Smith@cookcountyil.gov>,  Willie  Lewis  (Sheriff) 
<Willie.Lewis@cookcountyil.gov>,  Winston  Geralds  (Sheriff) 
<Winston.Geralds@cookcountyil.gov>,  Wyees  Williams  (Sheriff) 
<Wyees.Williams@cookcountyil.gov>,  Yamile  NoaSerna  (Sheriff) 
<Yamile.NoaSerna@cookcountyil.gov>,  Yashira  Rivas  (Sheriff) 
<Yashira.Rivas@cookcountyil.gov>,  Yolanda  Collins-Watson  (Sheriff) 
<Yolanda.Collins-Watson@cookcountyil.gov>,  Zachary  Almaoui  (Sheriff) 
<Zachary.Almaoui@cookcountyil.gov>,  Zachary  Smith  (Sheriff) 

<Zachary. Smith@cookcountyil.gov> 

Sent:  June  30,  2020  8:07:45  AM  CDT 

Received:  June  30,  2020  8:07:47  AM  CDT 

Attachments:  (U--FOUO)  MB  -  Criminal  Hackers  Target  US  Law  Enforcement  Data 

06262020.pdf 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated  June  29, 
2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a  hack-and-leak 
operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support  of  or  in  response  to 
nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years  of  data  from  200  police 
departments,  fusion  centers,  and  other  law  enforcement  training  and  support  resources  around  the  globe,  according 
to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack-and-leak  activity  against  the  Russian 
Government. 


If  you  no  longer  wish  to  be  on  this  distribution  list,  please  send  an  email  to  ccso.intel@cookcountyil.gov  to  discontinue  receiving 
these  emails.  If  you  would  like  any  member  under  your  command  to  receive  these  emails,  please  send  an  email  to 
ccso.intel@cookcountyil.gov  and  include  their  name,  title  and  email  address  in  the  body  of  the  request. 


Cook  County  Sheriffs  Office 
Strategic  Operations  Center 
3026  S.  California  Avenue 
Building  5,  2nd  Floor 
Chicago,  IL.  60608 
Office:  773-674-2694  or  8477 
Fax:  773-674-4797 


THIS  IS  A  CONFIDENTIAL  LAW  ENFORCEMENT  COMMUNICATION.  The  contents  of  this  e-mail  message  and  any 
attachments  are  intended  solely  for  the  addressee(s)  named  in  this  message.  This  communication  is  intended  to  be  and  to  remain 
confidential.  If  you  are  not  the  intended  recipient  of  this  message,  or  if  this  message  has  been  addressed  to  you  in  error,  please 
immediately  alert  the  sender  by  reply  e-mail  and  then  delete  this  message  and  its  attachments.  Do  not  deliver,  distribute,  transmit 
or  copy  this  message  and/or  any  attachments  and  if  you  are  not  the  intended  recipient,  do  not  disclose  the  contents  or  take  any 
action  relative  to  the  information  contained  in  this  communication  and/or  attachments.  This  e-mail  and  any  attached  documents 
may  contain  For  Official  Use  Only  and/or  Law  Enforcement  Sensitive  material  and  should  not  be  disseminated  outside  of  official 
law  enforcement  channels.  The  information  contained  in  this  message  as  well  as  any  attachments  shall  not  be  released  to  the 
media  or  the  general  public. 


[Heads  Up]  How  Slack  Phishing  Works  -  The  Latest  Tricky  Attack  Vector 

From:  CyberheistNews  <donotreply@cyberheistnews.com> 

To:  adnan.memon@cookcountyil.gov,  Adnan  Memon  (Sheriff) 

<Adnan.  Memon@cookcountyil.gov> 

Sent:  June  30,  2020  8:31 :54  AM  CDT 

Received:  June  30,  2020  8:32:12  AM  CDT 


External  Message  Disclaimer 

!  This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 


[Heads  Up]  How  Slack  Phishing  Works  -  The  Latest  Tricky  Attack  Vector 
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[Heads  Up]  How  Slack  Phishing  Works  -  The  Latest 
T ricky  Attack  Vector 

People  need  to  be  able  to  use  their  instincts  in  order  to  spot  new 
phishing  techniques,  according  to  Ashley  Graves,  a  Cloud 
Security  Researcher  at  AT&T  Alien  Labs.  On  the  CyberWire’s 
Research  Saturday  podcast,  Graves  described  a  phishing 
technique  that  abuses  webhooks  in  Slack  to  fool  users  into 
granting  an  attacker  access  to  their  Slack  data. 


A  webhook  is  a  feature  that  allows  third-party  apps  to  send  messages  to  a  specific 
Slack  channel  via  a  unique  URL.  Anyone  can  send  a  message  to  the  Slack  channel  if 
they  know  this  URL,  so  it’s  important  that  the  URL  be  kept  secret.  If  an  attacker 
discovers  a  leaked  webhook  URL,  they  can  craft  a  phishing  message  and  send  it 
directly  into  a  Slack  workspace  to  trick  a  user  into  installing  a  malicious  app.  This  app 
can  then  exfiltrate  data  from  the  targeted  workspace. 


Graves  emphasized  that  this  attack  doesn’t  have  any  visible  warning  signs,  since  the 
communication  comes  directly  from  Slack  through  a  legitimate  service. 


“The  only  indication  that  exists  would  be  the  person's  gut  feeling  that  it  doesn't  seem 
right,  that  this  app  should  not  be  requesting  this  level  of  data,”  she  said. 


Graves  said  part  of  the  solution  is  improved  awareness  around  what  attackers  can  do 
with  certain  information.  “So,  I  think  some  people  legitimately  don't  understand  how 


much  access  an  attacker  can  gain  when  credentials  are  leaked,  and  even  more  so 
when  a  webhook  secret  is  leaked,”  Graves  explained. 

“On  the  other  side  of  it  is  understanding  what  you're  giving  third  parties  access  to.  So, 
knowing  to  read  those  OAuth  scopes,  understanding  how  the  application  that  you're 
using  might  use  that  access.  Like,  it  wouldn't  make  sense  -  to  me,  at  least  -  for  a 
webhook  to  need  access  to  my  documents. 

So,  that's  something  that  they  have  to  look  over  and  have  some  sort  of  understanding 
around  whether  it's  some  self-learning,  whether  it's  included  in  security  awareness 
training  or  something  like  that.” 

Graves  noted  that  anyone  can  be  fooled  by  social  engineering,  so  companies  need  to 
ensure  that  users  know  when  they  should  be  cautious  and  ask  for  assistance  before 
taking  an  action. 

“But  again,  we've  seen  in  similar  attacks  in  the  past  that  users  can  be  easily  tricked  and 
that  it's  not  stupidity,”  she  said.  “It's  not  even  ignorance.  It's  just  that  this  is  very  new 
technology  to  a  lot  of  people,  and  the  prompts  are  not  always  clear,  and  there  is  a  lot  of 
small  text  about  how  they  work.  So  I  think  that  companies  need  to,  I  suppose,  make  as 
much  effort  as  possible  to  help  people  understand  the  impact  of  their  actions.” 

Attackers  will  never  stop  coming  up  with  new  ways  to  dupe  people  into  granting  them 
access.  New-school  security  awareness  training  can  give  your  employees  a  healthy 
sense  of  suspicion  to  enable  them  to  stop  social  engineering  attacks. 

The  CyberWire  has  the  story: 

https://thecyberwire.com/podcasts/research-saturday/140/transcript 

[Live  Demo]  Ridiculously  Easy  Security  Awareness 
Training  and  Phishing 

Old-school  awareness  training  does  not  hack  it  anymore.  Your  email  filters  have  an 
average  7-10%  failure  rate;  you  need  a  strong  human  firewall  as  your  last  line  of 
defense. 

Join  us  Wednesday,  July  8  @  2:00  pm  (ET),  for  a  live  demonstration  of  how 
KnowBe4  introduces  a  new-school  approach  to  Security  Awareness  Training  and 
Simulated  Phishing. 

See  how  easy  it  is  to  train  and  phish  your  users: 


•  Train  your  users  with  access  to  the  world's  largest  library  of  1000+  pieces  of 
awareness  training  content. 

•  Send  fully  automated  simulated  phishing  attacks,  including  thousands  of 
customizable  templates  with  unlimited  usage. 

•  NEW!  Brandable  Content  feature  gives  you  the  option  to  add  branded  custom 
content  to  select  training  modules. 

•  Assessments  allows  you  to  find  out  where  your  users  are  in  both  security 
knowledge  and  security  culture  to  help  establish  baseline  security  metrics  you 
can  improve  over  time. 


•  Advanced  Reporting  on  60+  key  awareness  training  indicators. 

•  Active  Directory  Integration  to  easily  upload  user  data,  eliminating  the  need  to 
manually  manage  user  changes. 

Find  out  how  33,000+  organizations  have  mobilized  their  end-users  as  their  human 
firewall. 

Date/Time:  Wednesday,  July  8  @  2:00  pm  (ET) 

Save  My  Spot! 

https://event.on24.eom/wcc/r/2439681/925D004197E678DDCC946A93B31C24D97par 

tnerref=CHN2 

[ALERT]  A  New  Devilish  Malware  Worm  Called  Lucifer  Is 
Targeting  Your  Windows  Workstations 

Palo  Alto  Networks’  Unit  42  Security  experts  have  identified  a  malware  worm  called 
Lucifer,  that  targets  Windows  systems  with  cryptojacking  and  distributed  denial-of- 
service  (DDoS)  attacks. 

This  brand-new  strain  initially  tries  to  infect  PCs  by  bombarding  them  with  a  big  list  of 
known  exploits,  hoping  to  cash  in  on  unpatched  vulns.  While  patches  for  all  these 
critical  and  high-severity  bugs  exist,  the  organizations  infected  by  this  new  strain 
malware  had  not  applied  the  patches. 

“Lucifer  is  a  new  hybrid  of  cryptojacking  and  DDoS  malware  variant  that  leverages  old 
vulnerabilities  to  spread  and  perform  malicious  activities  on  Windows  platforms,”  Palo 
Alto  said  last  Wednesday  in  a  blog  post.  “Applying  the  updates  and  patches  to  the 
affected  software  are  strongly  advised.” 

The  exploits  Lucifer  is  using  include  Rejetto  HTTP  File  Server  (CVE-201 4-6287), 

Oracle  Weblogic  (CVE-201 7-1 0271),  ThinkPHP  RCE  (CVE-201 8-20062),  Apache 
Struts  (CVE-201 7-9791),  Laravel  framework  CVE-201 9-9081),  and  Microsoft  Windows 
(CVE-201 7-01 44,  CVE-201 7-0145,  and  CVE-201 7-8464). 

After  a  successful  exploit,  the  strain  connects  to  its  command-and-control  (C2)  server 
and  is  able  to  execute  any  commands  on  the  fully  pwned  device.  Some  "features" 
allow  the  malware  to  drop  an  XMRig  miner  and  launch  cryptojacking  attacks,  as  well  as 
collecting  interface  info  and  sending  the  miner  status  to  the  C2. 

The  malware  is  also  capable  of  self-propagation  with  worm-like  features. 

The  Threatpost  site  commented:  "It  scans  for  either  open  TCP  ports  (also  known  as 
port  1433)  or  open  Remote  Procedure  Call  (RPC)  ports  (also  known  as  port  135).  If 
either  of  these  ports  is  open,  the  malware  attempts  to  brute-force  the  login  using  a 
default  administrator  username  and  an  embedded  password  list  (a  full  list  of  the 
passwords  used  can  be  found  on  Unit42’s  analysis).  It  then  copies  and  runs  the 
malware  binary  on  the  remote  host  upon  successful  authentication. 

Please  forward  to  your  friends.  Blog  post  with  links  continued  here: 


https://blog.knowbe4.com/heads-up-a-new-devilish-malware-worm-called-lucifer-is- 

targeting-your-windows-workstations 

See  How  You  Can  Get  Audits  Done  in  Half  the  Time  at 
Half  the  Cost 

You  told  us  you  have  challenging  compliance  requirements,  not  enough  time  to  get 
audits  done,  and  keeping  up  with  risk  assessments  and  third-party  vendor  risk  is  a 
continuous  problem. 

We  listened!  KCM  now  has  Compliance,  Risk,  Policy  and  Vendor  Risk 
Management  modules,  transforming  KCM  into  a  full  SaaS  GRC  platform! 

Join  us  Wednesday,  July  8  @  1:00  PM  (ET),  for  a  30-minute  live  product 
demonstration  of  KnowBe4's  KCM  GRC  platform.  See  how  you  can  simplify  the 
challenges  of  managing  your  compliance  requirements  within  your  organization  and 
across  third-party  vendors  and  ease  your  burden  when  it's  time  for  risk  assessments 
and  audits. 


•  NEW!  Demonstrate  overall  progress  and  health  of  your  compliance  and  risk 
management  initiatives  with  custom  reports. 

•  Vet,  manage  and  monitor  your  third-party  vendors'  security  risk  requirements. 

•  Simplify  risk  management  with  an  intuitive  interface  and  simple  workflow 
based  on  the  well-recognized  NIST  800-30. 

•  Quick  implementation  with  pre-built  requirements  templates  for  the  most 
widely  used  regulations. 

•  Secure  evidence  repository  and  DocuLinks  giving  you  two  ways  of 
maintaining  audit  evidence  and  documentation. 

•  Dashboards  with  automated  reminders  to  quickly  see  what  tasks  have  been 
completed,  not  met,  and  past  due. 

Date/Time:  Wednesday,  July  8  @  1:00  PM  (ET) 

Save  My  Spot! 

https://event.on24.eom/wcc/r/2439682/58CC9CFF88DA458F08828606604A4E427part 

nerref=CHN2 

Cyber  Crime  Uses  Adobe  and  Samsung  Servers  to  Hide 
Their  Phishing  Attacks 

Researchers  at  Check  Point  have  observed  a  phishing  campaign  that,  to  avoid 
detection,  abused  servers  belonging  to  Adobe,  Samsung,  and  the  University  of  Oxford. 
The  attackers  used  several  layers  of  deception  to  disguise  their  phishing  emails  as 
legitimate. 

The  phishing  emails  purported  to  come  from  Microsoft  and  informed  recipients  that 


they’d  received  a  voicemail  on  their  Office  365  account.  If  the  user  clicked  the  link  in 
the  email,  they’d  be  redirected  through  a  legitimate  server  before  landing  on  a  spoofed 
Office  365  login  page  designed  to  steal  their  credentials. 

The  redirection  step  was  accomplished  using  an  Adobe  Campaign  open  redirect  link 
belonging  to  Samsung  Canada,  meant  for  the  company’s  email  campaigns.  Open 
redirects  enable  anyone  to  craft  a  URL  that  will  route  a  user  through  the  server  hosting 
the  URL  before  sending  them  on  to  the  specified  website. 

In  this  case,  the  attackers  used  the  open  redirect  link  from  Samsung’s  email  campaign 
for  Cyber  Monday  in  2018  and  modified  it  to  point  to  their  phishing  page. 

“The  technique  of  using  Adobe  Campaign  open  redirect  was  initially  discovered  in 
September  2019  on  the  domain  belonging  to  Adobe  itself,”  the  researchers  write.  “In 
the  last  few  months,  it’s  been  widely  abused  for  phishing  purposes.  To  evade 
detection,  attackers  abuse  open  and  reputable  Adobe  Campaign  servers  to  redirect 
potential  victims  to  their  own  phishing  websites. 

This  means  that  the  link  embedded  in  the  phishing  email  is  part  of  a  trusted  domain  - 
one  that  unknowingly  redirects  victims  to  the  phishing  website.” 

The  attackers  also  managed  to  abuse  the  University  of  Oxford’s  email  servers  to 
disguise  the  origin  of  the  emails.  “Using  legitimate  Oxford  SMTP  servers  allowed  the 
attackers  to  pass  the  reputation  check  for  the  sender  domain,”  Check  Point  says.  “In 
addition,  there  was  no  need  to  compromise  actual  email  accounts  to  send  phishing 
emails  because  they  could  generate  as  many  email  addresses  as  they  wanted.” 

Finally,  the  phishing  kit  itself  was  hosted  on  a  compromised  WordPress  site.  It  would 
generate  a  new  directory  for  each  visitor,  as  well  as  unique,  obfuscated  source  code  to 
avoid  detection  by  security  tools. 

“The  second  layer  of  redirection  is  used  to  distance  the  final  phishing  page  from  the 
original  email,”  the  researchers  explain.  “In  this  case,  the  attackers  used  several 
compromised  WordPress  sites  which  contain  malicious  redirect  code.  Introducing 
another  redirection  layer  enables  the  attackers  to  circumvent  security  solutions  that 
investigate  the  links  within  the  email. 

Thus  the  URL  within  the  email  points  to  a  WordPress  site  instead  of  a  suspicious- 
looking  phishing  page.”  Attackers  will  never  stop  finding  new  ways  to  defeat  security 
technologies.  New-school  security  awareness  training  can  give  your  organization  an 
essential  layer  of  defense  by  enabling  your  employees  to  recognize  phishing  emails 
that  make  it  through  your  filters. 

Check  Point  has  the  story: 

https://research.checkpoint.com/2020/phishing-campaign-exploits-samsung-adobe- 

and-oxford-servers/ 

[On-Demand]  10  Incredible  Ways  You  Can  Be  Hacked 
Through  Email  &  How  to  Stop  the  Bad  Guys 

Email  is  still  the  #1  attack  vector  the  bad  guys  use.  A  whopping  91%  of  cyberattacks 
start  with  a  phishing  email,  but  email  hacking  is  much  more  than  phishing  and 
launching  malware. 


In  this  on-demand  webinar  Roger  A.  Grimes,  KnowBe4's  Data-Driven  Defense 
Evangelist  and  security  expert  with  over  30-years  of  experience,  explores  10  ways 
hackers  use  social  engineering  to  trick  your  users  into  revealing  sensitive  data  or 
enabling  malicious  code  to  run.  Plus,  he  shares  a  hacking  demo  by  KnowBe4's 
Chief  Hacking  Officer  Kevin  Mitnick. 

Roger  will  teach  you: 


•  How  silent  malware  launches,  remote  password  hash  capture,  and  how  rogue 
rules  work 

•  Why  rogue  documents,  establishing  fake  relationships  and  getting  you  to 
compromise  your  ethics  are  so  effective 

•  Details  behind  clickjacking  and  web  beacons 

•  Actionable  steps  on  how  to  defend  against  them  all 

If  all  you  were  worried  about  were  phishing  attempts,  think  again! 
https://info.knowbe4.com/webinar-10-ways-hacked-email 

Let's  stay  safe  out  there. 

Warm  Regards, 

Stu  Sjouwerman 
Founder  and  CEO 
KnowBe4,  Inc 


PS:  Just  For  YOU.  We  just  added  2  new  training  modules  featuring  Roger  Grimes 
about  data-driven  defense: 

https://blog.knowbe4.com/new-training-modules-added-on-data-driven-defense 

PSS:  Need  to  educate  your  C-level  execs?  Here  are  five  cybersecurity  books  that 
everyone  should  — and  can —  read,  recommended  by  the  Wall  Street  Journal: 
https://www.wsj.com/articles/five-cybersecurity-books-that-everyone-shouldand- 
canread-1 1 592579360 


Quotes  of  the  Week 


"It  is  not  because  things  are  difficult  that  we  do  not  dare, 
it  is  because  we  do  not  dare  that  they  are  difficult. " 

-  Lucius  Annaeus  Seneca,  Philosopher,  Statesman,  Dramatist  (5  BC  -  65  AD) 


"I  am  always  doing  that  which  I  cannot  do,  in  order  that  I  may  learn  how  to  do  it. " 


-  Pablo  Picasso,  Artist  (1881  -  1973) 


Thanks  for  reading  CyberheistNews 

But  if  you  want  to  unsubscribe,  you  can  do  that  right  here 

You  can  read  CyberheistNews  online  at  our  Blog 

https://blog.knowbe4.com/cyberheistnews-vol-10-27-heads-up-how-slack- 

phishing-works-the-latest-tricky-attack-vector 


Security  News 


Pyongyang's  Phishing  With  Job  Offers 

An  attack  campaign  with  possible  ties  to  North  Korea’s  Lazarus  Group 
targeted  aerospace  and  military  companies  in  Europe  and  the  Middle  East 
with  spearphishing  attacks  late  last  year,  according  to  researchers  at  ESET. 

The  campaign,  which  the  researchers  call  “Operation  ln(ter)ception,”  used 
social  engineering  attacks  on  Linkedln  to  trick  employees  into  opening 
malware-laden  documents. 

“To  initiate  contact,  they  approached  the  targets  with  fictitious  job  offers 
using  Linked  In’s  messaging  feature,”  the  researchers  write.  “In  order  to 
appear  credible,  the  attackers  posed  as  representatives  of  well-known, 
existing  companies  in  the  aerospace  and  defense  industry. 

For  each  of  the  targeted  companies  we  investigated,  the  attackers  had 
created  a  separate  fake  Linkedln  account:  one  impersonating  an  HR 
manager  from  Collins  Aerospace  (formerly  Rockwell  Collins),  a  major  US 
supplier  of  aerospace  and  defense  products;  the  other  posing  as  an  HR 
representative  of  General  Dynamics,  another  large  US-based  corporation 
with  a  similar  focus.  “ 

Interestingly,  while  the  attackers’  primary  goal  was  espionage,  ESET 
observed  one  case  in  which  the  attackers  used  a  victim’s  email  account  in 
an  attempt  to  conduct  a  business  email  compromise  (BEC)  scam.  While 
BEC  attacks  are  usually  associated  with  criminals  rather  than  state- 
sponsored  groups,  North  Korean  cyber  actors  often  conduct  financially 
motivated  attacks  to  generate  revenue  for  their  heavily  sanctioned  regime. 

“Among  the  victim’s  emails,  the  attackers  found  communication  between 
the  victim  and  a  customer  regarding  an  unresolved  invoice,”  the 


researchers  explain.  “They  followed  up  the  conversation  and  urged  the 
customer  to  pay  the  invoice,  however,  to  a  different  bank  account  than 
previously  agreed,  to  which  the  customer  responded  with  some  inquiries. 

As  part  of  this  ruse,  the  attackers  registered  an  identical  domain  name  to 
that  of  the  compromised  company,  but  on  a  different  top-level  domain,  and 
used  an  email  associated  with  this  fake  domain  for  further  communication 
with  the  targeted  customer. 

The  attackers  did  not  respond  to  the  customer’s  inquiries  and  continued  to 
urge  them  to  pay.  Instead  of  paying  the  invoice,  however,  the  targeted 
customer  reached  out  to  the  correct  email  address  of  the  victim  for 
assistance,  thwarting  the  attackers’  attempt.  The  victim  recognized 
something  was  amiss  and  reported  the  communication  as  an  incident.” 

Sometimes  it’s  espionage,  and  sometimes  it’s  fraud.  Recognizing  the 
motive  can  help  recognize  the  attack.  New-school  security  awareness 
training  can  provide  your  employees  with  the  knowledge  they  need  to 
thwart  targeted  social  engineering  attacks. 

ESET  has  the  story: 

https://www.welivesecurity.com/2020/06/17/operation-interception- 

aerospace-military-companies-cyberspies/ 

Survey  Says... You've  Been  Pwned 

Survey  are  enticing,  and  so  are  survey  scams.  But  they’re  easy  to 
recognize  if  you  know  what  to  look  for,  according  to  Paul  Ducklin  at  Naked 
Security. 

Ducklin  describes  a  typical  survey  scam  that  Sophos  spotted  recently.  The 
scammers  impersonate  well-known  brands  and  offer  a  reward  to  users  that 
fill  out  a  survey.  Real  companies  use  these  surveys  as  well,  but  the  rewards 
from  a  legitimate  survey  are  very  small,  such  as  a  coupon  for  your  next 
order. 

The  fake  survey  asks  generic,  innocuous  questions  that  could  apply  to  any 
business,  and  allows  the  user  to  choose  their  answers  from  multiple-choice 
panels.  Throughout  this  process,  the  site  displays  the  text  “38  visitors  on 
this  page,”  and  “6  rewards  left”  to  induce  a  sense  of  urgency. 

After  completing  the  survey,  the  user  is  informed  that  they’ve  actually  won 
an  expensive  prize,  such  as  a  free  iPhone. 


At  the  final  page,  however,  it’s  revealed  that  the  user  will  have  to  pay  one 


dollar  as  a  delivery  fee  before  they  can  receive  their  prize.  To  do  this,  they’ll 
be  asked  to  enter  their  name,  address,  and  credit  card  information,  which 
will  be  sent  straight  to  the  scammers. 

Ducklin  stresses  that  no  matter  how  tempting  the  deal  is,  you  should  leave 
the  site  if  you  sense  anything  out  of  place.  Even  if  you  don’t  see  any 
warning  signs,  the  moment  a  site  asks  you  to  enter  any  sensitive 
information  should  be  your  cue  to  leave. 

“Remember,  if  you  are  taking  a  survey  and  you  see  anything  that  doesn’t 
add  up  -  anything  at  all  -  then  you  need  to  get  off  the  website  right  away 
before  you  get  sucked  into  giving  away  any  personal  information,”  Ducklin 
writes. 

“Legitimate  companies  and  genuine  surveys  should  be  clearly  explained  in 
advance,  so  if  the  goalposts  move  halfway  through,  you’re  being 
scammed.”  Ducklin  adds  that  common  sense,  awareness,  and  level¬ 
headedness  is  usually  all  that’s  needed  to  defeat  these  types  of  scams. 

“There  is  no  free  iPhone,”  he  says.  “Or  Android,  or  tablet,  or  laptop.  There 
just  isn’t.  Stores  don’t  hand  out  $1000  mobile  phones  in  return  for  you 
telling  them  whether  you  think  they  should  stay  open  later.  They  just  don’t. 
Follow  your  head  and  not  your  heart.” 

New-school  security  awareness  training  can  help  your  employees 
recognize  social  engineering  tactics  and  avoid  falling  for  scams. 

Naked  Security  has  the  story: 

https://nakedsecurity.sophos.com/2020/06/22/anatomy-of-a-survey-scam- 

how-innocent-questions-can-rip-you-off/ 

KnowBe4  Announcement:  New  Training  Modules 
Added  on  Data-Driven  Defense 

We  have  exciting  news  to  share!  Two  new  modules  have  been  released 
about  data-driven  defense,  both  featuring  Data-Driven  Evangelist  Roger 
Grimes.  Join  Roger  Grimes  as  he  introduces  the  overall  concepts  of  a  risk- 
analyzed,  data-driven  computer  defense,  as  conceptualized  in  his  book,  A 
Data-Driven  Computer  Defense:  A  Way  to  Improve  Any  Computer  Defense. 

These  brand-new  modules  cover  the  following: 


An  Introduction  to  Data-Driven  Defense:  Roger  discusses  the  basic 
principles  behind  a  data-driven  defense  and  what  most  companies 
get  wrong  about  cybersecurity  risk  and  why. 


•  Data-Driven  Defense:  Hackers  and  Why  They  Hack:  Roger 
discusses  the  different  types  of  hackers  and  their  motivations.  If 
you’re  going  to  fight  hackers,  it’s  best  if  you  understand  why  they 
hack  and  what  they  are  after. 

You  are  able  to  view  both  modules  in  the  ModStore.  Get  no-charge  access 
here: 

https://blog.knowbe4.com/new-training-modules-added-on-data-driven- 
defense _ 


The  10  Interesting  News  Items 
This  Week 


1.  This  ransomware  has  learned  a  new  trick:  Scanning  for  point  of 
sales  devices: 

https://www.zdnet.com/article/this-ransomware-has-learned-a-new- 

trick-scanning-for-point-of-sales-devices/ 

2.  Black  Hat  Survey:  Breach  Concerns  Hit  Record  Levels  Due  to 
COVID-19: 

https://www.darkreading.com/threat-intelligence/black-hat-survey- 
breach-concerns-hit-record-levels-due-to-covid-1 9/d/d-id/1 3381 67 

3.  Companies  Name  One  of  the  Biggest  Cybersecurity  Threats: 
Their  Employees  -  The  Wall  Street  Journal: 

https://www.wsj.com/articles/companies-name-one-of-the-biggest- 
cybersecurity-threats-their-employees-1 15926061 15? 

4.  Really  good  article  on  security  awareness  in  SC  Mag: 

https://www.scmagazine.com/infosec-world-2020/lululemons-rex- 

sarabia-works-up-a-sweat-building-a-security-awareness-program- 

from-scratch/ 

5.  FBI  warns  K12  schools  of  ransomware  attacks  via  RDP: 

https://www.zdnet.com/article/fbi-warns-k12-schools-of-ransomware- 

attacks-via-rdp/ 

6.  Don't  Fall  Victim  to  These  Common  Social  Networking  Scams. 
By  yours  truly  at  Forbes: 

https://www.forbes.eom/sites/forbestechcouncil/2020/06/24/dont-fall- 

victim-to-these-common-social-networking-scams/#259d5d6e5462 

7.  10  (more)  free  security  tools  worth  a  look  via  @csoonline: 

https://www.csoonline.com/article/3563872/10-more-free-security- 

tools-worth-a-look.html 


8.  Hackers  abuse  Samsung  Canada,  others,  to  launch  phishing 
attacks: 

https://research.checkpoint.com/2020/phishing-campaign-exploits- 

samsung-adobe-and-oxford-servers/ 

9.  Ransomware  operators  lurk  on  your  network  after  their  attack: 

https://www.bleepingcomputer.com/news/security/ransomware- 

operators-lurk-on-your-network-after-their-attack/ 

10.  Ouch.  BlueLeaks  data  dump  exposes  over  24  years  of  police 
records: 

https://www.bleepingcomputer.com/news/security/blueleaks-data- 
d  u  mp-exposes-over-24-years-of-pol  ice-records/ 


Cyberheist  'Fave'  Links 


This  Week's  Links  We  Like,  Tips,  Hints  and  Fun 
Stuff 


•  Your  Virtual  Vacation  this  week:  Eagle  Creek  Trail  -  Amazing 
Trip: 

https://www.youtube.com/watch?v=T5DzGrDp5Xw 

•  41  Next-Level  Hotels  To  Visit  Before  You  Die: 

https://www.youtube.com/watch?v=FdkxZLfvm6Y 

•  Ethiopia’s  Chapel  in  the  Sky: 

https://www.youtube.com/watch?v=IJCy64adY3Y 

•  44  Things  To  Add  To  Your  Thrill-Seeking  Bucket  List: 

https://www.youtube.com/watch?v=0EPk5o_yvKY 

•  How  '1917'  Was  Filmed  To  Look  Like  One  Shot.  Incredible 
cinematography: 

https://www.youtube.com/watch?v=kMBnvz-dEXw 

•  Danny  Macaskill:  Mountain  Biking  Over  The  Ridge: 

https://www.flixxy.com/danny-macaskill-mountain-biking-over-the- 

ridge.htm?utm_source=4 

•  Pursuit  -  A  4K  storm  time-lapse  film: 

https://www.youtube.com/watch?v=oagszCmJLpU 


•  Cats  wake  up  their  owner  by  cute  actions: 

https://www.youtube.com/watch?v=CL1Cdw_wtuk 

•  The  Golden  Retriever  Puppy  Attack: 

https://www.youtube.com/watch?v=Lc6db8qfZEw 

•  Got  a  Pest  Problem?  Call  the  Quack  Squad: 

https://www.youtube.com/watch?v=H6Ehoxu9QY8 

•  For  Da  Kids  #1:  How  Parrots  Express  Their  Affection: 

https://www.flixxy.com/how-parrots-express-their- 

affection.htm?utm_source=4 

•  For  Da  Kids  #2:  Einstein  the  African  Grey  Parrot  showed  off  her 
vocabulary  skills  with  a  200  sounds  and  words: 

https://www.flixxy.com/einstein-smart-parrot.htm?utm_source=4 

•  For  Da  Kids  #3:  CGI  Animated  Short  Film  "The  Box": 

https://www.youtube.com/watch?v=20evunLzSgk 
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[Heads  Up]  How  Slack  Phishing  Works  -  The  Latest 
T ricky  Attack  Vector 

People  need  to  be  able  to  use  their  instincts  in  order  to  spot  new 
phishing  techniques,  according  to  Ashley  Graves,  a  Cloud 
Security  Researcher  at  AT&T  Alien  Labs.  On  the  CyberWire’s 
Research  Saturday  podcast,  Graves  described  a  phishing 
technique  that  abuses  webhooks  in  Slack  to  fool  users  into 
granting  an  attacker  access  to  their  Slack  data. 


A  webhook  is  a  feature  that  allows  third-party  apps  to  send  messages  to  a  specific 
Slack  channel  via  a  unique  URL.  Anyone  can  send  a  message  to  the  Slack  channel  if 
they  know  this  URL,  so  it’s  important  that  the  URL  be  kept  secret.  If  an  attacker 
discovers  a  leaked  webhook  URL,  they  can  craft  a  phishing  message  and  send  it 
directly  into  a  Slack  workspace  to  trick  a  user  into  installing  a  malicious  app.  This  app 
can  then  exfiltrate  data  from  the  targeted  workspace. 


Graves  emphasized  that  this  attack  doesn’t  have  any  visible  warning  signs,  since  the 
communication  comes  directly  from  Slack  through  a  legitimate  service. 


“The  only  indication  that  exists  would  be  the  person's  gut  feeling  that  it  doesn't  seem 
right,  that  this  app  should  not  be  requesting  this  level  of  data,”  she  said. 


Graves  said  part  of  the  solution  is  improved  awareness  around  what  attackers  can  do 
with  certain  information.  “So,  I  think  some  people  legitimately  don't  understand  how 


much  access  an  attacker  can  gain  when  credentials  are  leaked,  and  even  more  so 
when  a  webhook  secret  is  leaked,”  Graves  explained. 

“On  the  other  side  of  it  is  understanding  what  you're  giving  third  parties  access  to.  So, 
knowing  to  read  those  OAuth  scopes,  understanding  how  the  application  that  you're 
using  might  use  that  access.  Like,  it  wouldn't  make  sense  -  to  me,  at  least  -  for  a 
webhook  to  need  access  to  my  documents. 

So,  that's  something  that  they  have  to  look  over  and  have  some  sort  of  understanding 
around  whether  it's  some  self-learning,  whether  it's  included  in  security  awareness 
training  or  something  like  that.” 

Graves  noted  that  anyone  can  be  fooled  by  social  engineering,  so  companies  need  to 
ensure  that  users  know  when  they  should  be  cautious  and  ask  for  assistance  before 
taking  an  action. 

“But  again,  we've  seen  in  similar  attacks  in  the  past  that  users  can  be  easily  tricked  and 
that  it's  not  stupidity,”  she  said.  “It's  not  even  ignorance.  It's  just  that  this  is  very  new 
technology  to  a  lot  of  people,  and  the  prompts  are  not  always  clear,  and  there  is  a  lot  of 
small  text  about  how  they  work.  So  I  think  that  companies  need  to,  I  suppose,  make  as 
much  effort  as  possible  to  help  people  understand  the  impact  of  their  actions.” 

Attackers  will  never  stop  coming  up  with  new  ways  to  dupe  people  into  granting  them 
access.  New-school  security  awareness  training  can  give  your  employees  a  healthy 
sense  of  suspicion  to  enable  them  to  stop  social  engineering  attacks. 

The  CyberWire  has  the  story: 

https://thecyberwire.com/podcasts/research-saturday/140/transcript 

[Live  Demo]  Ridiculously  Easy  Security  Awareness 
Training  and  Phishing 

Old-school  awareness  training  does  not  hack  it  anymore.  Your  email  filters  have  an 
average  7-10%  failure  rate;  you  need  a  strong  human  firewall  as  your  last  line  of 
defense. 

Join  us  Wednesday,  July  8  @  2:00  pm  (ET),  for  a  live  demonstration  of  how 
KnowBe4  introduces  a  new-school  approach  to  Security  Awareness  Training  and 
Simulated  Phishing. 

See  how  easy  it  is  to  train  and  phish  your  users: 


•  Train  your  users  with  access  to  the  world's  largest  library  of  1000+  pieces  of 
awareness  training  content. 

•  Send  fully  automated  simulated  phishing  attacks,  including  thousands  of 
customizable  templates  with  unlimited  usage. 

•  NEW!  Brandable  Content  feature  gives  you  the  option  to  add  branded  custom 
content  to  select  training  modules. 

•  Assessments  allows  you  to  find  out  where  your  users  are  in  both  security 
knowledge  and  security  culture  to  help  establish  baseline  security  metrics  you 
can  improve  over  time. 


•  Advanced  Reporting  on  60+  key  awareness  training  indicators. 

•  Active  Directory  Integration  to  easily  upload  user  data,  eliminating  the  need  to 
manually  manage  user  changes. 

Find  out  how  33,000+  organizations  have  mobilized  their  end-users  as  their  human 
firewall. 

Date/Time:  Wednesday,  July  8  @  2:00  pm  (ET) 

Save  My  Spot! 

https://event.on24.eom/wcc/r/2439681/925D004197E678DDCC946A93B31C24D97par 

tnerref=CHN2 

[ALERT]  A  New  Devilish  Malware  Worm  Called  Lucifer  Is 
Targeting  Your  Windows  Workstations 

Palo  Alto  Networks’  Unit  42  Security  experts  have  identified  a  malware  worm  called 
Lucifer,  that  targets  Windows  systems  with  cryptojacking  and  distributed  denial-of- 
service  (DDoS)  attacks. 

This  brand-new  strain  initially  tries  to  infect  PCs  by  bombarding  them  with  a  big  list  of 
known  exploits,  hoping  to  cash  in  on  unpatched  vulns.  While  patches  for  all  these 
critical  and  high-severity  bugs  exist,  the  organizations  infected  by  this  new  strain 
malware  had  not  applied  the  patches. 

“Lucifer  is  a  new  hybrid  of  cryptojacking  and  DDoS  malware  variant  that  leverages  old 
vulnerabilities  to  spread  and  perform  malicious  activities  on  Windows  platforms,”  Palo 
Alto  said  last  Wednesday  in  a  blog  post.  “Applying  the  updates  and  patches  to  the 
affected  software  are  strongly  advised.” 

The  exploits  Lucifer  is  using  include  Rejetto  HTTP  File  Server  (CVE-201 4-6287), 

Oracle  Weblogic  (CVE-201 7-1 0271),  ThinkPHP  RCE  (CVE-201 8-20062),  Apache 
Struts  (CVE-201 7-9791),  Laravel  framework  CVE-201 9-9081),  and  Microsoft  Windows 
(CVE-201 7-01 44,  CVE-201 7-0145,  and  CVE-201 7-8464). 

After  a  successful  exploit,  the  strain  connects  to  its  command-and-control  (C2)  server 
and  is  able  to  execute  any  commands  on  the  fully  pwned  device.  Some  "features" 
allow  the  malware  to  drop  an  XMRig  miner  and  launch  cryptojacking  attacks,  as  well  as 
collecting  interface  info  and  sending  the  miner  status  to  the  C2. 

The  malware  is  also  capable  of  self-propagation  with  worm-like  features. 

The  Threatpost  site  commented:  "It  scans  for  either  open  TCP  ports  (also  known  as 
port  1433)  or  open  Remote  Procedure  Call  (RPC)  ports  (also  known  as  port  135).  If 
either  of  these  ports  is  open,  the  malware  attempts  to  brute-force  the  login  using  a 
default  administrator  username  and  an  embedded  password  list  (a  full  list  of  the 
passwords  used  can  be  found  on  Unit42’s  analysis).  It  then  copies  and  runs  the 
malware  binary  on  the  remote  host  upon  successful  authentication. 

Please  forward  to  your  friends.  Blog  post  with  links  continued  here: 


https://blog.knowbe4.com/heads-up-a-new-devilish-malware-worm-called-lucifer-is- 

targeting-your-windows-workstations 

See  How  You  Can  Get  Audits  Done  in  Half  the  Time  at 
Half  the  Cost 

You  told  us  you  have  challenging  compliance  requirements,  not  enough  time  to  get 
audits  done,  and  keeping  up  with  risk  assessments  and  third-party  vendor  risk  is  a 
continuous  problem. 

We  listened!  KCM  now  has  Compliance,  Risk,  Policy  and  Vendor  Risk 
Management  modules,  transforming  KCM  into  a  full  SaaS  GRC  platform! 

Join  us  Wednesday,  July  8  @  1:00  PM  (ET),  for  a  30-minute  live  product 
demonstration  of  KnowBe4's  KCM  GRC  platform.  See  how  you  can  simplify  the 
challenges  of  managing  your  compliance  requirements  within  your  organization  and 
across  third-party  vendors  and  ease  your  burden  when  it's  time  for  risk  assessments 
and  audits. 


•  NEW!  Demonstrate  overall  progress  and  health  of  your  compliance  and  risk 
management  initiatives  with  custom  reports. 

•  Vet,  manage  and  monitor  your  third-party  vendors'  security  risk  requirements. 

•  Simplify  risk  management  with  an  intuitive  interface  and  simple  workflow 
based  on  the  well-recognized  NIST  800-30. 

•  Quick  implementation  with  pre-built  requirements  templates  for  the  most 
widely  used  regulations. 

•  Secure  evidence  repository  and  DocuLinks  giving  you  two  ways  of 
maintaining  audit  evidence  and  documentation. 

•  Dashboards  with  automated  reminders  to  quickly  see  what  tasks  have  been 
completed,  not  met,  and  past  due. 

Date/Time:  Wednesday,  July  8  @  1:00  PM  (ET) 

Save  My  Spot! 

https://event.on24.eom/wcc/r/2439682/58CC9CFF88DA458F08828606604A4E427part 

nerref=CHN2 

Cyber  Crime  Uses  Adobe  and  Samsung  Servers  to  Hide 
Their  Phishing  Attacks 

Researchers  at  Check  Point  have  observed  a  phishing  campaign  that,  to  avoid 
detection,  abused  servers  belonging  to  Adobe,  Samsung,  and  the  University  of  Oxford. 
The  attackers  used  several  layers  of  deception  to  disguise  their  phishing  emails  as 
legitimate. 

The  phishing  emails  purported  to  come  from  Microsoft  and  informed  recipients  that 


they’d  received  a  voicemail  on  their  Office  365  account.  If  the  user  clicked  the  link  in 
the  email,  they’d  be  redirected  through  a  legitimate  server  before  landing  on  a  spoofed 
Office  365  login  page  designed  to  steal  their  credentials. 

The  redirection  step  was  accomplished  using  an  Adobe  Campaign  open  redirect  link 
belonging  to  Samsung  Canada,  meant  for  the  company’s  email  campaigns.  Open 
redirects  enable  anyone  to  craft  a  URL  that  will  route  a  user  through  the  server  hosting 
the  URL  before  sending  them  on  to  the  specified  website. 

In  this  case,  the  attackers  used  the  open  redirect  link  from  Samsung’s  email  campaign 
for  Cyber  Monday  in  2018  and  modified  it  to  point  to  their  phishing  page. 

“The  technique  of  using  Adobe  Campaign  open  redirect  was  initially  discovered  in 
September  2019  on  the  domain  belonging  to  Adobe  itself,”  the  researchers  write.  “In 
the  last  few  months,  it’s  been  widely  abused  for  phishing  purposes.  To  evade 
detection,  attackers  abuse  open  and  reputable  Adobe  Campaign  servers  to  redirect 
potential  victims  to  their  own  phishing  websites. 

This  means  that  the  link  embedded  in  the  phishing  email  is  part  of  a  trusted  domain  - 
one  that  unknowingly  redirects  victims  to  the  phishing  website.” 

The  attackers  also  managed  to  abuse  the  University  of  Oxford’s  email  servers  to 
disguise  the  origin  of  the  emails.  “Using  legitimate  Oxford  SMTP  servers  allowed  the 
attackers  to  pass  the  reputation  check  for  the  sender  domain,”  Check  Point  says.  “In 
addition,  there  was  no  need  to  compromise  actual  email  accounts  to  send  phishing 
emails  because  they  could  generate  as  many  email  addresses  as  they  wanted.” 

Finally,  the  phishing  kit  itself  was  hosted  on  a  compromised  WordPress  site.  It  would 
generate  a  new  directory  for  each  visitor,  as  well  as  unique,  obfuscated  source  code  to 
avoid  detection  by  security  tools. 

“The  second  layer  of  redirection  is  used  to  distance  the  final  phishing  page  from  the 
original  email,”  the  researchers  explain.  “In  this  case,  the  attackers  used  several 
compromised  WordPress  sites  which  contain  malicious  redirect  code.  Introducing 
another  redirection  layer  enables  the  attackers  to  circumvent  security  solutions  that 
investigate  the  links  within  the  email. 

Thus  the  URL  within  the  email  points  to  a  WordPress  site  instead  of  a  suspicious- 
looking  phishing  page.”  Attackers  will  never  stop  finding  new  ways  to  defeat  security 
technologies.  New-school  security  awareness  training  can  give  your  organization  an 
essential  layer  of  defense  by  enabling  your  employees  to  recognize  phishing  emails 
that  make  it  through  your  filters. 

Check  Point  has  the  story: 

https://research.checkpoint.com/2020/phishing-campaign-exploits-samsung-adobe- 

and-oxford-servers/ 

[On-Demand]  10  Incredible  Ways  You  Can  Be  Hacked 
Through  Email  &  How  to  Stop  the  Bad  Guys 

Email  is  still  the  #1  attack  vector  the  bad  guys  use.  A  whopping  91%  of  cyberattacks 
start  with  a  phishing  email,  but  email  hacking  is  much  more  than  phishing  and 
launching  malware. 


In  this  on-demand  webinar  Roger  A.  Grimes,  KnowBe4's  Data-Driven  Defense 
Evangelist  and  security  expert  with  over  30-years  of  experience,  explores  10  ways 
hackers  use  social  engineering  to  trick  your  users  into  revealing  sensitive  data  or 
enabling  malicious  code  to  run.  Plus,  he  shares  a  hacking  demo  by  KnowBe4's 
Chief  Hacking  Officer  Kevin  Mitnick. 

Roger  will  teach  you: 


•  How  silent  malware  launches,  remote  password  hash  capture,  and  how  rogue 
rules  work 

•  Why  rogue  documents,  establishing  fake  relationships  and  getting  you  to 
compromise  your  ethics  are  so  effective 

•  Details  behind  clickjacking  and  web  beacons 

•  Actionable  steps  on  how  to  defend  against  them  all 

If  all  you  were  worried  about  were  phishing  attempts,  think  again! 
https://info.knowbe4.com/webinar-10-ways-hacked-email 

Let's  stay  safe  out  there. 

Warm  Regards, 

Stu  Sjouwerman 
Founder  and  CEO 
KnowBe4,  Inc 


PS:  Just  For  YOU.  We  just  added  2  new  training  modules  featuring  Roger  Grimes 
about  data-driven  defense: 

https://blog.knowbe4.com/new-training-modules-added-on-data-driven-defense 

PSS:  Need  to  educate  your  C-level  execs?  Here  are  five  cybersecurity  books  that 
everyone  should  — and  can —  read,  recommended  by  the  Wall  Street  Journal: 
https://www.wsj.com/articles/five-cybersecurity-books-that-everyone-shouldand- 
canread-1 1 592579360 


Quotes  of  the  Week 


"It  is  not  because  things  are  difficult  that  we  do  not  dare, 
it  is  because  we  do  not  dare  that  they  are  difficult. " 

-  Lucius  Annaeus  Seneca,  Philosopher,  Statesman,  Dramatist  (5  BC  -  65  AD) 


"I  am  always  doing  that  which  I  cannot  do,  in  order  that  I  may  learn  how  to  do  it. " 


-  Pablo  Picasso,  Artist  (1881  -  1973) 


Thanks  for  reading  CyberheistNews 

But  if  you  want  to  unsubscribe,  you  can  do  that  right  here 

You  can  read  CyberheistNews  online  at  our  Blog 

https://blog.knowbe4.com/cyberheistnews-vol-10-27-heads-up-how-slack- 

phishing-works-the-latest-tricky-attack-vector 


Security  News 


Pyongyang's  Phishing  With  Job  Offers 

An  attack  campaign  with  possible  ties  to  North  Korea’s  Lazarus  Group 
targeted  aerospace  and  military  companies  in  Europe  and  the  Middle  East 
with  spearphishing  attacks  late  last  year,  according  to  researchers  at  ESET. 

The  campaign,  which  the  researchers  call  “Operation  ln(ter)ception,”  used 
social  engineering  attacks  on  Linkedln  to  trick  employees  into  opening 
malware-laden  documents. 

“To  initiate  contact,  they  approached  the  targets  with  fictitious  job  offers 
using  Linked  In’s  messaging  feature,”  the  researchers  write.  “In  order  to 
appear  credible,  the  attackers  posed  as  representatives  of  well-known, 
existing  companies  in  the  aerospace  and  defense  industry. 

For  each  of  the  targeted  companies  we  investigated,  the  attackers  had 
created  a  separate  fake  Linkedln  account:  one  impersonating  an  HR 
manager  from  Collins  Aerospace  (formerly  Rockwell  Collins),  a  major  US 
supplier  of  aerospace  and  defense  products;  the  other  posing  as  an  HR 
representative  of  General  Dynamics,  another  large  US-based  corporation 
with  a  similar  focus.  “ 

Interestingly,  while  the  attackers’  primary  goal  was  espionage,  ESET 
observed  one  case  in  which  the  attackers  used  a  victim’s  email  account  in 
an  attempt  to  conduct  a  business  email  compromise  (BEC)  scam.  While 
BEC  attacks  are  usually  associated  with  criminals  rather  than  state- 
sponsored  groups,  North  Korean  cyber  actors  often  conduct  financially 
motivated  attacks  to  generate  revenue  for  their  heavily  sanctioned  regime. 

“Among  the  victim’s  emails,  the  attackers  found  communication  between 
the  victim  and  a  customer  regarding  an  unresolved  invoice,”  the 


researchers  explain.  “They  followed  up  the  conversation  and  urged  the 
customer  to  pay  the  invoice,  however,  to  a  different  bank  account  than 
previously  agreed,  to  which  the  customer  responded  with  some  inquiries. 

As  part  of  this  ruse,  the  attackers  registered  an  identical  domain  name  to 
that  of  the  compromised  company,  but  on  a  different  top-level  domain,  and 
used  an  email  associated  with  this  fake  domain  for  further  communication 
with  the  targeted  customer. 

The  attackers  did  not  respond  to  the  customer’s  inquiries  and  continued  to 
urge  them  to  pay.  Instead  of  paying  the  invoice,  however,  the  targeted 
customer  reached  out  to  the  correct  email  address  of  the  victim  for 
assistance,  thwarting  the  attackers’  attempt.  The  victim  recognized 
something  was  amiss  and  reported  the  communication  as  an  incident.” 

Sometimes  it’s  espionage,  and  sometimes  it’s  fraud.  Recognizing  the 
motive  can  help  recognize  the  attack.  New-school  security  awareness 
training  can  provide  your  employees  with  the  knowledge  they  need  to 
thwart  targeted  social  engineering  attacks. 

ESET  has  the  story: 

https://www.welivesecurity.com/2020/06/17/operation-interception- 

aerospace-military-companies-cyberspies/ 

Survey  Says... You've  Been  Pwned 

Survey  are  enticing,  and  so  are  survey  scams.  But  they’re  easy  to 
recognize  if  you  know  what  to  look  for,  according  to  Paul  Ducklin  at  Naked 
Security. 

Ducklin  describes  a  typical  survey  scam  that  Sophos  spotted  recently.  The 
scammers  impersonate  well-known  brands  and  offer  a  reward  to  users  that 
fill  out  a  survey.  Real  companies  use  these  surveys  as  well,  but  the  rewards 
from  a  legitimate  survey  are  very  small,  such  as  a  coupon  for  your  next 
order. 

The  fake  survey  asks  generic,  innocuous  questions  that  could  apply  to  any 
business,  and  allows  the  user  to  choose  their  answers  from  multiple-choice 
panels.  Throughout  this  process,  the  site  displays  the  text  “38  visitors  on 
this  page,”  and  “6  rewards  left”  to  induce  a  sense  of  urgency. 

After  completing  the  survey,  the  user  is  informed  that  they’ve  actually  won 
an  expensive  prize,  such  as  a  free  iPhone. 


At  the  final  page,  however,  it’s  revealed  that  the  user  will  have  to  pay  one 


dollar  as  a  delivery  fee  before  they  can  receive  their  prize.  To  do  this,  they’ll 
be  asked  to  enter  their  name,  address,  and  credit  card  information,  which 
will  be  sent  straight  to  the  scammers. 

Ducklin  stresses  that  no  matter  how  tempting  the  deal  is,  you  should  leave 
the  site  if  you  sense  anything  out  of  place.  Even  if  you  don’t  see  any 
warning  signs,  the  moment  a  site  asks  you  to  enter  any  sensitive 
information  should  be  your  cue  to  leave. 

“Remember,  if  you  are  taking  a  survey  and  you  see  anything  that  doesn’t 
add  up  -  anything  at  all  -  then  you  need  to  get  off  the  website  right  away 
before  you  get  sucked  into  giving  away  any  personal  information,”  Ducklin 
writes. 

“Legitimate  companies  and  genuine  surveys  should  be  clearly  explained  in 
advance,  so  if  the  goalposts  move  halfway  through,  you’re  being 
scammed.”  Ducklin  adds  that  common  sense,  awareness,  and  level¬ 
headedness  is  usually  all  that’s  needed  to  defeat  these  types  of  scams. 

“There  is  no  free  iPhone,”  he  says.  “Or  Android,  or  tablet,  or  laptop.  There 
just  isn’t.  Stores  don’t  hand  out  $1000  mobile  phones  in  return  for  you 
telling  them  whether  you  think  they  should  stay  open  later.  They  just  don’t. 
Follow  your  head  and  not  your  heart.” 

New-school  security  awareness  training  can  help  your  employees 
recognize  social  engineering  tactics  and  avoid  falling  for  scams. 

Naked  Security  has  the  story: 

https://nakedsecurity.sophos.com/2020/06/22/anatomy-of-a-survey-scam- 

how-innocent-questions-can-rip-you-off/ 

KnowBe4  Announcement:  New  Training  Modules 
Added  on  Data-Driven  Defense 

We  have  exciting  news  to  share!  Two  new  modules  have  been  released 
about  data-driven  defense,  both  featuring  Data-Driven  Evangelist  Roger 
Grimes.  Join  Roger  Grimes  as  he  introduces  the  overall  concepts  of  a  risk- 
analyzed,  data-driven  computer  defense,  as  conceptualized  in  his  book,  A 
Data-Driven  Computer  Defense:  A  Way  to  Improve  Any  Computer  Defense. 

These  brand-new  modules  cover  the  following: 


An  Introduction  to  Data-Driven  Defense:  Roger  discusses  the  basic 
principles  behind  a  data-driven  defense  and  what  most  companies 
get  wrong  about  cybersecurity  risk  and  why. 


•  Data-Driven  Defense:  Hackers  and  Why  They  Hack:  Roger 
discusses  the  different  types  of  hackers  and  their  motivations.  If 
you’re  going  to  fight  hackers,  it’s  best  if  you  understand  why  they 
hack  and  what  they  are  after. 

You  are  able  to  view  both  modules  in  the  ModStore.  Get  no-charge  access 
here: 

https://blog.knowbe4.com/new-training-modules-added-on-data-driven- 
defense _ 


The  10  Interesting  News  Items 
This  Week 


1.  This  ransomware  has  learned  a  new  trick:  Scanning  for  point  of 
sales  devices: 

https://www.zdnet.com/article/this-ransomware-has-learned-a-new- 

trick-scanning-for-point-of-sales-devices/ 

2.  Black  Hat  Survey:  Breach  Concerns  Hit  Record  Levels  Due  to 
COVID-19: 

https://www.darkreading.com/threat-intelligence/black-hat-survey- 
breach-concerns-hit-record-levels-due-to-covid-1 9/d/d-id/1 3381 67 

3.  Companies  Name  One  of  the  Biggest  Cybersecurity  Threats: 
Their  Employees  -  The  Wall  Street  Journal: 

https://www.wsj.com/articles/companies-name-one-of-the-biggest- 
cybersecurity-threats-their-employees-1 15926061 15? 

4.  Really  good  article  on  security  awareness  in  SC  Mag: 

https://www.scmagazine.com/infosec-world-2020/lululemons-rex- 

sarabia-works-up-a-sweat-building-a-security-awareness-program- 

from-scratch/ 

5.  FBI  warns  K12  schools  of  ransomware  attacks  via  RDP: 

https://www.zdnet.com/article/fbi-warns-k12-schools-of-ransomware- 

attacks-via-rdp/ 

6.  Don't  Fall  Victim  to  These  Common  Social  Networking  Scams. 
By  yours  truly  at  Forbes: 

https://www.forbes.eom/sites/forbestechcouncil/2020/06/24/dont-fall- 

victim-to-these-common-social-networking-scams/#259d5d6e5462 

7.  10  (more)  free  security  tools  worth  a  look  via  @csoonline: 

https://www.csoonline.com/article/3563872/10-more-free-security- 

tools-worth-a-look.html 


8.  Hackers  abuse  Samsung  Canada,  others,  to  launch  phishing 
attacks: 

https://research.checkpoint.com/2020/phishing-campaign-exploits- 

samsung-adobe-and-oxford-servers/ 

9.  Ransomware  operators  lurk  on  your  network  after  their  attack: 

https://www.bleepingcomputer.com/news/security/ransomware- 

operators-lurk-on-your-network-after-their-attack/ 

10.  Ouch.  BlueLeaks  data  dump  exposes  over  24  years  of  police 
records: 

https://www.bleepingcomputer.com/news/security/blueleaks-data- 
d  u  mp-exposes-over-24-years-of-pol  ice-records/ 


Cyberheist  'Fave'  Links 


This  Week's  Links  We  Like,  Tips,  Hints  and  Fun 
Stuff 


•  Your  Virtual  Vacation  this  week:  Eagle  Creek  Trail  -  Amazing 
Trip: 

https://www.youtube.com/watch?v=T5DzGrDp5Xw 

•  41  Next-Level  Hotels  To  Visit  Before  You  Die: 

https://www.youtube.com/watch?v=FdkxZLfvm6Y 

•  Ethiopia’s  Chapel  in  the  Sky: 

https://www.youtube.com/watch?v=IJCy64adY3Y 

•  44  Things  To  Add  To  Your  Thrill-Seeking  Bucket  List: 

https://www.youtube.com/watch?v=0EPk5o_yvKY 

•  How  '1917'  Was  Filmed  To  Look  Like  One  Shot.  Incredible 
cinematography: 

https://www.youtube.com/watch?v=kMBnvz-dEXw 

•  Danny  Macaskill:  Mountain  Biking  Over  The  Ridge: 

https://www.flixxy.com/danny-macaskill-mountain-biking-over-the- 

ridge.htm?utm_source=4 

•  Pursuit  -  A  4K  storm  time-lapse  film: 

https://www.youtube.com/watch?v=oagszCmJLpU 


•  Cats  wake  up  their  owner  by  cute  actions: 

https://www.youtube.com/watch?v=CL1Cdw_wtuk 

•  The  Golden  Retriever  Puppy  Attack: 

https://www.youtube.com/watch?v=Lc6db8qfZEw 

•  Got  a  Pest  Problem?  Call  the  Quack  Squad: 

https://www.youtube.com/watch?v=H6Ehoxu9QY8 

•  For  Da  Kids  #1:  How  Parrots  Express  Their  Affection: 

https://www.flixxy.com/how-parrots-express-their- 

affection.htm?utm_source=4 

•  For  Da  Kids  #2:  Einstein  the  African  Grey  Parrot  showed  off  her 
vocabulary  skills  with  a  200  sounds  and  words: 

https://www.flixxy.com/einstein-smart-parrot.htm?utm_source=4 

•  For  Da  Kids  #3:  CGI  Animated  Short  Film  "The  Box": 

https://www.youtube.com/watch?v=20evunLzSgk 


FOLLOW  US  ON:  Twitter  |  Linkedln  |  YouTube 
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Don't  like  to  click?  Email  opt-out  requests  should  be  : 


Undeliverable:  Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law 
Enforcement  Data 


From:  Microsoft  Outlook 

<MicrosoftExchange329e71ec88ae4615bbc36ab6ce41 109e@cookcounty.onmicrosoft.com 


To: 


Sent: 

Received: 

Attachments 


CCSO.INTEL@cookcountyil.gov,  Daniel.Moreci@cookcountyil.gov, 
Darren.Makowski@cookcountyil.gov,  Dennis.Nicpan@cookcountyil.gov, 
James.Dillon@cookcountyil.gov,  John.Hammond@cookcountyil.gov, 
Joseph.Giunta@cookcountyil.gov,  Leonard.Jagielski@cookcountyil.gov, 
Miles.Cooperman@cookcountyil.gov,  Patrick.Hecker@cookcountyil.gov, 
Richard.OBrien1@cookcountyil.gov,  Richard.Young2@cookcountyil.gov, 
Joseph.Danzl@cookcountyil.gov,  Zelda.Whittler@cookcountyil.gov 
June  30,  2020  8:40:36  AM  CDT 
June  30,  2020  8:40:37  AM  CDT 

Pass  Through  -  (U//F0U0)  Criminal  Hackers  Target  US  Law  Enforcement  Data 


CCCASV02.CCOUNTY.com  rejected  your  message  to  the  following  email  addresses: 

Daniel.Mored@cookcountyil.gov 

Something  went  wrong  and  your  message  couldn't  be  delivered.  This  could  be  a  temporary  issue. 
Try  resending  the  message  in  a  few  minutes.  If  that  doesn't  work,  forward  this  message  to  your 
email  admin. 

For  Email  Admins 

The  message  couldn't  be  delivered  because  a  mail  routing  loop  was  encountered.  This  may  be 
due  to  a  routing  misconfiguration  in  the  mail  flow  settings  for  either  your  organization  or  the 
recipient  organization.  If  mail  flow  settings  were  recently  updated,  this  error  may  be  temporary. 

Check  the  message  headers  in  the  section  below  to  determine  where  the  loop  may  be  occurring 
and  if  it's  something  you  or  the  email  admin  for  the  recipient  organization  can  fix. 

For  more  information,  see  Error  code  5.4.12  in  Exchange  Online  and  Office  365. 


CCCASV02.CCOUNTY.com  gave  this  error: 

SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 

<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com> 

Darren.Makowski@cookcountvil.gov 

Something  went  wrong  and  your  message  couldn't  be  delivered.  This  could  be  a  temporary  issue. 
Try  resending  the  message  in  a  few  minutes.  If  that  doesn't  work,  forward  this  message  to  your 
email  admin. 

For  Email  Admins 

The  message  couldn't  be  delivered  because  a  mail  routing  loop  was  encountered.  This  may  be 
due  to  a  routing  misconfiguration  in  the  mail  flow  settings  for  either  your  organization  or  the 
recipient  organization.  If  mail  flow  settings  were  recently  updated,  this  error  may  be  temporary. 

Check  the  message  headers  in  the  section  below  to  determine  where  the  loop  may  be  occurring 
and  if  it's  something  you  or  the  email  admin  for  the  recipient  organization  can  fix. 

For  more  information,  see  Error  code  5.4.12  in  Exchange  Online  and  Office  365. 


CCCASV02.CCOUNTY.com  gave  this  error: 

SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 

<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com> 

Dennis.Nicpan@cookcounWil.gov 

Something  went  wrong  and  your  message  couldn't  be  delivered.  This  could  be  a  temporary  issue. 
Try  resending  the  message  in  a  few  minutes.  If  that  doesn't  work,  forward  this  message  to  your 
email  admin. 

For  Email  Admins 

The  message  couldn't  be  delivered  because  a  mail  routing  loop  was  encountered.  This  may  be 
due  to  a  routing  misconfiguration  in  the  mail  flow  settings  for  either  your  organization  or  the 
recipient  organization.  If  mail  flow  settings  were  recently  updated,  this  error  may  be  temporary. 

Check  the  message  headers  in  the  section  below  to  determine  where  the  loop  may  be  occurring 
and  if  it's  something  you  or  the  email  admin  for  the  recipient  organization  can  fix. 

For  more  information,  see  Error  code  5.4.12  in  Exchange  Online  and  Office  365. 


CCCASV02.CCOUNTY.com  gave  this  error: 

SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 

<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com> 

James.Dillon@cookcountyil.gov 

Something  went  wrong  and  your  message  couldn't  be  delivered.  This  could  be  a  temporary  issue. 
Try  resending  the  message  in  a  few  minutes.  If  that  doesn't  work,  forward  this  message  to  your 
email  admin. 

For  Email  Admins 

The  message  couldn't  be  delivered  because  a  mail  routing  loop  was  encountered.  This  may  be 
due  to  a  routing  misconfiguration  in  the  mail  flow  settings  for  either  your  organization  or  the 
recipient  organization.  If  mail  flow  settings  were  recently  updated,  this  error  may  be  temporary. 

Check  the  message  headers  in  the  section  below  to  determine  where  the  loop  may  be  occurring 
and  if  it's  something  you  or  the  email  admin  for  the  recipient  organization  can  fix. 

For  more  information,  see  Error  code  5.4.12  in  Exchange  Online  and  Office  365. 


CCCASV02.CCOUNTY.com  gave  this  error: 

SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 

<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com> 

John.Hammond@cookcounWil.gov 

Something  went  wrong  and  your  message  couldn't  be  delivered.  This  could  be  a  temporary  issue. 
Try  resending  the  message  in  a  few  minutes.  If  that  doesn't  work,  forward  this  message  to  your 
email  admin. 

For  Email  Admins 

The  message  couldn't  be  delivered  because  a  mail  routing  loop  was  encountered.  This  may  be 
due  to  a  routing  misconfiguration  in  the  mail  flow  settings  for  either  your  organization  or  the 
recipient  organization.  If  mail  flow  settings  were  recently  updated,  this  error  may  be  temporary. 

Check  the  message  headers  in  the  section  below  to  determine  where  the  loop  may  be  occurring 
and  if  it's  something  you  or  the  email  admin  for  the  recipient  organization  can  fix. 

For  more  information,  see  Error  code  5.4.12  in  Exchange  Online  and  Office  365. 


CCCASV02.CCOUNTY.com  gave  this  error: 

SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 

<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com> 

Joseph.Giunta@cookcountvil.gov 

Something  went  wrong  and  your  message  couldn't  be  delivered.  This  could  be  a  temporary  issue. 
Try  resending  the  message  in  a  few  minutes.  If  that  doesn't  work,  forward  this  message  to  your 
email  admin. 

For  Email  Admins 

The  message  couldn't  be  delivered  because  a  mail  routing  loop  was  encountered.  This  may  be 
due  to  a  routing  misconfiguration  in  the  mail  flow  settings  for  either  your  organization  or  the 
recipient  organization.  If  mail  flow  settings  were  recently  updated,  this  error  may  be  temporary. 

Check  the  message  headers  in  the  section  below  to  determine  where  the  loop  may  be  occurring 
and  if  it's  something  you  or  the  email  admin  for  the  recipient  organization  can  fix. 

For  more  information,  see  Error  code  5.4.12  in  Exchange  Online  and  Office  365. 


CCCASV02.CCOUNTY.com  gave  this  error: 

SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 

<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com> 

LeonardJaaielski@cookcountyil.gov 

Something  went  wrong  and  your  message  couldn't  be  delivered.  This  could  be  a  temporary  issue. 
Try  resending  the  message  in  a  few  minutes.  If  that  doesn't  work,  forward  this  message  to  your 
email  admin. 

For  Email  Admins 

The  message  couldn't  be  delivered  because  a  mail  routing  loop  was  encountered.  This  may  be 
due  to  a  routing  misconfiguration  in  the  mail  flow  settings  for  either  your  organization  or  the 
recipient  organization.  If  mail  flow  settings  were  recently  updated,  this  error  may  be  temporary. 

Check  the  message  headers  in  the  section  below  to  determine  where  the  loop  may  be  occurring 
and  if  it's  something  you  or  the  email  admin  for  the  recipient  organization  can  fix. 

For  more  information,  see  Error  code  5.4.12  in  Exchange  Online  and  Office  365. 


CCCASV02.CCOUNTY.com  gave  this  error: 

SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 

<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com> 

Miles.Cooperman@cookcountvil.gov 

Something  went  wrong  and  your  message  couldn't  be  delivered.  This  could  be  a  temporary  issue. 
Try  resending  the  message  in  a  few  minutes.  If  that  doesn't  work,  forward  this  message  to  your 
email  admin. 

For  Email  Admins 

The  message  couldn't  be  delivered  because  a  mail  routing  loop  was  encountered.  This  may  be 
due  to  a  routing  misconfiguration  in  the  mail  flow  settings  for  either  your  organization  or  the 
recipient  organization.  If  mail  flow  settings  were  recently  updated,  this  error  may  be  temporary. 

Check  the  message  headers  in  the  section  below  to  determine  where  the  loop  may  be  occurring 
and  if  it's  something  you  or  the  email  admin  for  the  recipient  organization  can  fix. 

For  more  information,  see  Error  code  5.4.12  in  Exchange  Online  and  Office  365. 


CCCASV02.CCOUNTY.com  gave  this  error: 

SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 

<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com> 

Patrick.Hecker@cookcountvil.gov 

Something  went  wrong  and  your  message  couldn't  be  delivered.  This  could  be  a  temporary  issue. 
Try  resending  the  message  in  a  few  minutes.  If  that  doesn't  work,  forward  this  message  to  your 
email  admin. 

For  Email  Admins 

The  message  couldn't  be  delivered  because  a  mail  routing  loop  was  encountered.  This  may  be 
due  to  a  routing  misconfiguration  in  the  mail  flow  settings  for  either  your  organization  or  the 
recipient  organization.  If  mail  flow  settings  were  recently  updated,  this  error  may  be  temporary. 

Check  the  message  headers  in  the  section  below  to  determine  where  the  loop  may  be  occurring 
and  if  it's  something  you  or  the  email  admin  for  the  recipient  organization  can  fix. 

For  more  information,  see  Error  code  5.4.12  in  Exchange  Online  and  Office  365. 


CCCASV02.CCOUNTY.com  gave  this  error: 

SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 

<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com> 

Richard.OBrienl@cookcountyil.gov 

Something  went  wrong  and  your  message  couldn't  be  delivered.  This  could  be  a  temporary  issue. 
Try  resending  the  message  in  a  few  minutes.  If  that  doesn't  work,  forward  this  message  to  your 
email  admin. 

For  Email  Admins 

The  message  couldn't  be  delivered  because  a  mail  routing  loop  was  encountered.  This  may  be 
due  to  a  routing  misconfiguration  in  the  mail  flow  settings  for  either  your  organization  or  the 
recipient  organization.  If  mail  flow  settings  were  recently  updated,  this  error  may  be  temporary. 

Check  the  message  headers  in  the  section  below  to  determine  where  the  loop  may  be  occurring 
and  if  it's  something  you  or  the  email  admin  for  the  recipient  organization  can  fix. 

For  more  information,  see  Error  code  5.4.12  in  Exchange  Online  and  Office  365. 


CCCASV02.CCOUNTY.com  gave  this  error: 

SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 

<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com> 

Richard.Young2@cookcountvil.gov 

Something  went  wrong  and  your  message  couldn't  be  delivered.  This  could  be  a  temporary  issue. 
Try  resending  the  message  in  a  few  minutes.  If  that  doesn't  work,  forward  this  message  to  your 
email  admin. 

For  Email  Admins 

The  message  couldn't  be  delivered  because  a  mail  routing  loop  was  encountered.  This  may  be 
due  to  a  routing  misconfiguration  in  the  mail  flow  settings  for  either  your  organization  or  the 
recipient  organization.  If  mail  flow  settings  were  recently  updated,  this  error  may  be  temporary. 

Check  the  message  headers  in  the  section  below  to  determine  where  the  loop  may  be  occurring 
and  if  it's  something  you  or  the  email  admin  for  the  recipient  organization  can  fix. 

For  more  information,  see  Error  code  5.4.12  in  Exchange  Online  and  Office  365. 


CCCASV02.CCOUNTY.com  gave  this  error: 

SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 

<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com> 

Joseph.Danzl@cookcountvil.gov 

Something  went  wrong  and  your  message  couldn't  be  delivered.  This  could  be  a  temporary  issue. 
Try  resending  the  message  in  a  few  minutes.  If  that  doesn't  work,  forward  this  message  to  your 
email  admin. 

For  Email  Admins 

The  message  couldn't  be  delivered  because  a  mail  routing  loop  was  encountered.  This  may  be 
due  to  a  routing  misconfiguration  in  the  mail  flow  settings  for  either  your  organization  or  the 
recipient  organization.  If  mail  flow  settings  were  recently  updated,  this  error  may  be  temporary. 

Check  the  message  headers  in  the  section  below  to  determine  where  the  loop  may  be  occurring 
and  if  it's  something  you  or  the  email  admin  for  the  recipient  organization  can  fix. 

For  more  information,  see  Error  code  5.4.12  in  Exchange  Online  and  Office  365. 


CCCASV02.CCOUNTY.com  gave  this  error: 

SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 

<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com> 

Zelda .  Whittler@cookcountyi  I  .gov 

Something  went  wrong  and  your  message  couldn't  be  delivered.  This  could  be  a  temporary  issue. 
Try  resending  the  message  in  a  few  minutes.  If  that  doesn't  work,  forward  this  message  to  your 
email  admin. 

For  Email  Admins 

The  message  couldn't  be  delivered  because  a  mail  routing  loop  was  encountered.  This  may  be 
due  to  a  routing  misconfiguration  in  the  mail  flow  settings  for  either  your  organization  or  the 
recipient  organization.  If  mail  flow  settings  were  recently  updated,  this  error  may  be  temporary. 

Check  the  message  headers  in  the  section  below  to  determine  where  the  loop  may  be  occurring 
and  if  it's  something  you  or  the  email  admin  for  the  recipient  organization  can  fix. 

For  more  information,  see  Error  code  5.4.12  in  Exchange  Online  and  Office  365. 


CCCASV02.CCOUNTY.com  gave  this  error: 

SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 

<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com> 


Diagnostic  information  for  administrators: 

Generating  server:  DM6PR09MB5192.namprd09.prod.outlook.com 

Daniel.Moreci@cookcountyil.gov 

CCCASV02.CCOUNTY.com 

Remote  Server  returned  '554  5.4.12  SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 
<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com>' 


Da  rren .  Ma  kowski  @cookcou  ntyi  I .  gov 
CCCASV02.CCOUNTY.com 

Remote  Server  returned  '554  5.4.12  SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 
<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com>' 

Dennis.Nicpan@cookcountyil.gov 

CCCASV02.CCOUNTY.com 

Remote  Server  returned  '554  5.4.12  SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 
<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com>' 

James.Dillon@cookcountyil.gov 

CCCASV02.CCOUNTY.com 

Remote  Server  returned  '554  5.4.12  SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 
<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com>' 

John.Hammond@cookcountyil.gov 

CCCASV02.CCOUNTY.com 

Remote  Server  returned  '554  5.4.12  SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 
<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com>' 

Joseph.Giunta@cookcountyil.gov 

CCCASV02.CCOUNTY.com 

Remote  Server  returned  '554  5.4.12  SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 
<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com>' 

Leonard.Jagielski@cookcountyil.gov 

CCCASV02.CCOUNTY.com 

Remote  Server  returned  '554  5.4.12  SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 
<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com>' 

Miles.Cooperman@cookcountyil.gov 

CCCASV02.CCOUNTY.com 

Remote  Server  returned  '554  5.4.12  SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 
<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com>' 

Patrick.Hecker@cookcountyil.gov 

CCCASV02.CCOUNTY.com 

Remote  Server  returned  '554  5.4.12  SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 
<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com>' 

Richard.OBrienl@cookcountyil.gov 

CCCASV02.CCOUNTY.com 

Remote  Server  returned  '554  5.4.12  SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 
<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com>' 

Richard.Young2@cookcountyil.gov 

CCCASV02.CCOUNTY.com 

Remote  Server  returned  '554  5.4.12  SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 
<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com>' 

Joseph.Danzl@cookcountyil.gov 

CCCASV02.CCOUNTY.com 

Remote  Server  returned  '554  5.4.12  SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 
<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com>' 

Zelda.Whittler@cookcountyil.gov 

CCCASV02.CCOUNTY.com 

Remote  Server  returned  '554  5.4.12  SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 
<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com>' 

Original  message  headers: 

Received:  from  CY4PR09CA0013.namprd09.prod.outlook.com  (2603 : 10b6 : 910 : 2% 123) 
by  DM6PR09MB5192.namprd09.prod.outlook.com  (2603 : 10b6 : 5 : 273 : : 18)  with 
Microsoft  SMTP  Server  (version-- TI.S1_2 , 

cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384)  id  15.20.3131.21;  Tue,  30  Jun 


2020  13:40:34  +0000 

Received :  from  CY1GCC01FT004  . eop-gccOl .prod .protection .outlook . com 
(2a01: 111 : f 400 : 7d02 : :209)  by  CY4PR09CA0013 . outlook-office365.com 
(2603 : 10b6 : 910 : 2 : : 23)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipftet=TISmECDHE_RSAJWITirAES_256_GCM_SHA384)  id  15.20.3131.21  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:40:33  +0000 
Authentication-Results:  spf=softfail  (sender  IP' is  162U2i*7>  184 . 79) 
smtp .mailfrom=cookcountyil . gov;  cookcountyil.gov;  dkim=none  (message  not 
signed)  header . d=none; cookcountyil . gov;  dmarc=fail  action=none 
header . from  -cookcountyil . gov; 

Received-SPF:  SoftFail  (protection.outlook.com:  domain  of  transitioning 
cookcountyil.gov  discourages  use  of  1 62. 217. 184. 79  as  permitted  sender) 
Received:  from  CCCASV01.CCOUNTY.com  (162.217.184.79)  by 
CY1GCC01FT004  .mail -.protection. outlook. com  (10.97.0.246)  with  Microsoft  SMTP 
Server  (versioa-TLSl_2,  cipher=TLS_EC‘DHE__RSA_WITH_AES_128_GCM_SHA2.56)  id 
15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:40:33  +0000 
Received:  fromCCCASV02.CC0UNaY.com  (10.124.40.40)  byCCCASV01.CCOUNTY.com 

(10.124.40.39)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 

cipher=TI.S_ECDflE<_RSA_WITH_AES_128_GCM_SHA256)  id  15.1.1261  .35;  Tue,  30  Jun 
2020  08:39:59  -0500 

Received:  from  GCC02-BL0-obe.outbound.protection.outlook.com  (10.124.186.250) 
by  CCCASV02 . CCOUKTY . com  (10.124.40.40)  Kith  Microsoft  SMTP  Server 
(version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 
15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:39:59  -0500 
Received:  from  MWHPR09CA0043.namprd09.prod.outlook.com  (2603 : 10b6 : 300 : 6d: : 29) 
by  BYAPR09MB3304.namprd09.prod.outlook.com  (2603 : 10b6 : a03 : 9e : : 33)  with 
Microsoft  SMTP  Server  (vers.ion-UT.Sl_2 , 

cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3131.25;  Tue,  30  Jun 
2020  13:39:56  +0000 

Received:  from  DM2GCC01FT005 . eop-gccOl .prod. protection . outlook.com 
(2a01  :  111 :  f  4  00  :  7c01  :200)  by  MWHPRO  9CA0  04  3.  outlook  .  of  fice365  .  com 
(2603 : 10b6 : 300 : 6d: : 29)  with  Microsoft  SMTP  Server  (version-TLSl_2y 
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3153.20  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:39:56  +0000 
Authentication-Results-Original :  spf=softfail  (sender  IP  is  162.217.184.79) 
smtp .mailf rom— QQOkcoUntyii , gov;  cookcountyil,, gov;  dkiiftpuiope  (message  not 
sighed)  header. d=ftone; cookcountyil. gov;  dmarc=fail  act io'n -.ngne 
header . f rom=cookcountyil . gov; 

Received-SPF:  SoftFail  (protectioft.outlook.com:  domaift.  of  transitioning 
cookcountyil.gov  discourages  use  of  162.217.184.79  as  permitted  sender) 
Received:  fromCCCASV02.CCOUNTY.com  (162,217.184.79)  by 
DM2GCC01FT005.mail.protection.outlook.com  (10.97.3.0)  with  Microsoft  SMTP 
Server  (version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 
15.20.3131.20  via  Frontend  Transport;  Tue,  30  JUn  2020  13:39:56  +0000 
Received:  from  CCCASV02.CCOUNTY.com  (10.124.40.40)  by  CCCASV02.CCOUNTY.com 

(10.124.40.40)  with  Microsoft  SMTP  Server  (version-  TLS1_2 , 

cipher=TLS_ECDHE_RSA_WITH_AES_12 8_GCM_SHA2 5 6 )  id  15.1.1261.35;  Tue,  30  Jun 
2020  08:24:50  -0500 

Received:  from  GCC02-BL0-obe. outbound. protection, outlook. com  (10.124.186,250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(vers ion  TLS1_2,  c iph e r-TI, S_ECDH E_R S A_W LTR_AK S_1 2 8_GCM_SHA2 56)  id 
15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:24:50  -0500 
Received:  from  MWHPR09CA0042.namprd09.prod.outlook.com  (2 603 : 10b6 : 300 : 6d : : 28 ) 
by  BY5PR09MB4929.namprd09.prod.outlook.com  (2603 : 10b6 : a03 : 247 : : 1 4 )  with 
Microsoft  SMTP  Server  (version=TLSl_2 , 

cipher-TlS_EC-DHE_RSA_Wl’I  H  A?iS_256_GCM_SHA384 )  id  15.20.3131  .20;  Tue,  30  Jun 
2020  13:24:48  +0000 

Received :  from  DM2GCC01 FT007 . eop-gccOl .prod. protection . cutl ook . com 
(2a01:lll:f400:7d01: :200)  by  MWHPR09CA0042.outlook.office365.com 
(2603 : 10b6: 300 : 6d: : 28)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
ciphesr-Tj,S_BCDHE_RSA_WITH^AES_256_GCM_SHA384)  id  15.20.3131.21  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:24:48  +0000 
Au there! cat ion- Re sults-Criginal :  spf  softfail  ( sender  IP  is  162.217.184.79) 
smtp ,mailfrom=cookcountyil . gov;  cookcountyil.gov;  dkim=none  (message  not 
sighed)  header . d— none; cookcountyil . gov;  dmarc=fail  actioft+hwne 
header . from- -cookcountyil . gov; 

Received-SPF:  SoftFail  (protection.outlook.com:  domain  of  transitioning 


cookcountyil.gov  discourages  use  of  162.217.184.79  as  permitted  sender) 
Received:  from  CCCASV02.CCOJNTY.com  (162.217.184.79)  by 
bM2GCC0lFT007.mail.protectidn.outlook.com  (10.97.3.159)  with  Microsoft  SMTP 
Server  (version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 

15.20.3131.20  via  Frontend  Transport?  Tue,  30  Jun  2020  13:24:47  +0000 
Received:  from  CCCASV02.CCOUNTY.com  (10.124.40.40)  by  CCCASV02.CCOUNTY.com 
(10.124.40.40)  with  Microsoft  SMTP  Server  (versibn=TiiSi_21, 

cipher=TLS_ECDHE_RSA_WITH_AES_12 8_GCM_SHA2 5 6 )  id  15.1.1261.35;  Tue,  30  Jun 
2020  08:09:37  -0500 

Received:  from  GCC02-DM3-obe.outbound.protection.outlQok.com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(version-TLSl_2 ,  ciphe^TfS_ECDHE_RSA_Wl¥li_AES_128_GCM_SHA2 56 )  id 
15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:09:36  -0500 
Received:  from  CY4PR09CA0094.namprd09.prod.outlook.com  (2603 : 10b6 : 903 : c7 : : 32 ) 
by  DM6PR09MB5863.namprd09.prOd.outlook.com  (2 603 : 10b6 : 5 : 271 : : 7 )  with 
Microsoft  SMTP  Server  (version=TLSl_2 , 

cipher ~T  1  S_F, C DH E_R S A_V\M  T B  A?iS_256_GCM_SHA384  )  id  15.20.3131.21,;  Tue,  30  Jun 
2020  13:09:35  +0000 

Received:  from  DM2GCC01FT007 . eop-gcc01.prOd.protection.OUtlook.com 
(2a01 : 111 : f 400 : 7d01 : : 207)  by  CY4PR09CA0094 . outlook, of fice3 65 . com 
(2603 : 10b6 : 903 : c7 : : 32 )  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher-5TiS_ECDBR_RSA_WITl^&lS_256_GCM_SHA384)  id  15.20.3153.20  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:09:34  +0000 
Authentication— Resulfs-Original :  spf=softfail  (sender  IP  is  162.217 . 184 .79) 
smtp ,mailfrom=cookcountyil . gov;  cookcountyil.gov;  dkim=none  (message  not 
signed)  header . d=none; cookcountyil . gov;  dmarc=fail  action=none 
header . from  ••ccokcountyi 1 . gov; 

Received-SPF:  SoftFail  (protection.outlook.com:  domain  of  transitioning 
cookcountyil .gov  discourages  use  of  1  62. 2 17. 184. 79  as  permitted  sender) 
Received:  from  CCCASV01.CCOUNTY.com  (162.217.184.79)  by 
DM2GCC01 Fi 007 .mail .prcrecti.on.outlook.com  (10.97.3.159)  with  Microsoft  SMTP 
Server  (vers ioh^TfS  1  _2 ,  ciphejr=TLS^OBSE_RSA_WITH__AES_128_GCM_SHA256)  id 

15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:09:34  +0000 
Received:  fromCCCASV02.CCOUNTY.com  (10.124.40.40)  byCCCASV01.CCOUNTY.com 
(10.124.40.39)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher=TT.S_£CBBE_RSA_WITH_AES_128_GCM_SHA256)  id  15.1  .1261  .35;  Tue,  30  Jun 
2020  08:08:33  -0500 

Received:  from  GCC02-DM3-obe.outbound.protection.outlook.com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 
15.1 .1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:08:33  -0500 
Received:  from  BL2PR09CA0040.namprd09.prod.outlook.com 
(2a01:lll:e400:c743::50)  by  MN2PR09MB5003 . namprd09.prod.outlook.com 
(2603:10b.6 :208:21a: :7)  with  Microsoft  SMTP  Server  (version=TLST_2, 
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3131.20;  Tue,  30  Jun 
2020  13:08:31  +0000 

Received:  from  DM2GCC01FT005 . eop-gccOl .prod. protection . outlook.com 
(2a01 :111 : f 400 : 7d01 : : 205)  by  BL2PR09CA0040 . outlook . of fi ee365 . com 
(2a01 :  111 :  e400  :  c743  :  :  50 )  with  Microsoft  SMTP  Server  (vers i  cn--TLS1  _2 , 
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3153.20  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:08:31  +0000 
Authentication-Results-Original :  spf=softfail  (sender  IP  is  162.217.184.79) 
smtp.mailfroi!ir=idb0kcountyii-,gov;  cookcountyil.gov;  dkijjMnsne  (message  not 
signed)  header. d=none; codkcountyil . gov;  dmarc=fail  a  c  t  i  on  thd  n  e 
header . f rom=cookcountyil . gov; 

Received-SPF:  SoftFail  (protection, outlook. com:  domain  of  transitioning 
cookcountyil.gov  discourages  use  of  162.217.184.79  as  permitted  sender) 
Received:  fromCCCASV01.CC0UNTY.com  (162.217.184.79)  by 
DM2GCC01FT005.mail.protection.outlook.com  (10.97.3.0)  with  Microsoft  SMTP 
Server  (version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 

15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:08:31  +0000 
Received:  from  CCCASV02.CCOUNTY.com  (10.124.40.40)  by  CCCASV01.CCOUNTY.com 
(10.124.40.39)  with  Microsoft  SMTP  Server  (version  JT, Si  2 , 

cipher=TLS_ECDHE_RSA_WITH_AES_12 8_GCM_SHA2 5 6 )  id  15.1.1261.35;  Tue,  30  Jun 
2020  08:08:27  -0500 

Received:  from  GCC02-BL0-obe. outbound. protection,outlook. com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 


(version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 

15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jan  2020  08:08:27  -0500 
Received :  from  BN6PR09CA0061.namprd09.prod.outlook.com  (2603 : 10b6 : 404 : 7a: : 23) 

by  SA9PR09MB4784.namprd09.prod.outlook.com  (2 603 : 10b6 : 806 : lc : : 21 )  with 
Microsoft  SMTP  Server  (version-TT,Sl_2 , 

cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384)  id  15.20.3131.21;  Tue,  30  Jun 
2020  13:08:25  +0000 

Received:  from  DM2GCC01FT010 . eop-gccOl .prod. protection . outlook.com 
(2a01:lll:f400:7d01: :203)  by  BN6PR09CA0061.outlook.office365.com 
(2603 :T0b6 : 4  04 : 7a : : 23 )  with  Microsoft  SMTP  Server  (vers  ion- ’TLS1._2 , 
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384)  id  15.20.3153.20  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:08:25  +0000 
Authentication-Results-Original :  spf=softfail  (sender  IP  is  162.217.184.79) 
smtp.mailfrom~bOokcountyii.gov;  cookeouhtyil.gov;  'dkim^nbne  (message  not 
signed)  header  ,d=none;  cookcountyil.gov;  dmarc=fail  a e t i on  ='n 6 r, e 
header . f rom=cookcountyil . gov; 

Received-SPF:  SoftFail  (protection, outlook. com:  domain  of  transitioning 
cookcountyil.gov  discourages  use  of  162.217.184.79  as  permitted  sender) 
Received:  fromCCCASV02.CCOUNTY.com  (162.217.184.79)  by 
DM2GCC01FT010 .mail, protection, outlook. com  (10.97.3.132)  with  Microsoft  SMTP 
Server  (version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 
15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:08:25  +0000 
Received:  from  CCCASV02.CCOUNTY.com  (10.124.40.40)  by  CCCASV02.CCOUNTY.com 
(10.124.40.40)  with  Microsoft  SMTP  Server  (version  -TLS1  2 , 

cipher=TLS_ECDHE_RSA_WITH_AES_12 8_GCM_SHA2 5 6 )  id  15.1.1261.35;  Tue,  30  Jun 
2020  08:07:52  -0500 

Received:  from  GCC02-BL0-obe.outbound.protection.oatl0ok.com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
( versions'll, SI  _2 ,  cipher  TLSJ-;CD9E_RSA_W  ITH_AES_1 2 8_GCM_SHA2 5 6 )  id 

15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:07:52  -0500 
Received:  from  BL0PR0901CA0029.namprd09.prod.outlook.com 

(2603:1 0b6:208:lc0::39)  by  MW 2 PR0901 MB3689 . namprd09.prod.outlopk.com 
(2603 : 10b6 : 302 : 12 : : 14 )  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher=TJ,S  E'ODiCfr.RSA_WITa_teS_256_GCM_SHA384)  id  15.20.3131.23;  Tue,  30  Jun 
2020  13:07:49  +0000 

Received:  from  DM2GCC01FT00 6 .eop-gccOl .prod. protection, outlook,  com 
(2a01:lll:f400:7d01: :2Q3)  by  BL0PR0901CA0029.outlook.office365.com 
(2603 : 10b6 : 208 : IcO : : 39)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher-Tis_icWE_RSA_WITH_AES_256_GCM_SHA384)  id  15.20.3153.20  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:07:49  +0000 
Authentication-ResUlts-Original :  spf=softfail  (sender  TP  is  162.217.184.79) 
smtp ,mailfrom=cookcountyil . gov;  cookcountyil.gov;  dkim=none  (message  not 
signed)  header . d=none; cookeountyil . gov;  dmarc=fail  action=none 
header . from -cookeountyil . gov; 

Received-SPF:  SoftFail  (protection.outlook.com:  domain  of  transitioning 
cookeountyil . gov  discourages  use  of  162. 217. 184. 79  as  permitted  sender) 
Received:  from  CCCASV01.CCOUNTY.com  (162.217.184.79)  by 
DM2GCC01FT006.mailLtprotection.oatlook.com  (10.97.3.107)  with.  Microsoft  SMTP 
Server  (version=TLSl_2 ,  ciphe,r’=TLS->EC'DRE_RSA_WITR_AES_128_GCM_SHA256)  id 
15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:07:49  +0000 
Received:  from  CCCASV02 . CCOUNTY .  com  (10.124.40.40)  byCCCASV01.CCOUNTY.com 
(10.124.40.39)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher=TLS_ECD.&S'  RSA_WITH_AES_128_GCM_SHA256)  id  15.1.1261.35;  Tue,  30  Jun 
2020  08:07:18  -0500 

Received:  from  GCC02-BL0-obe.outbound.protection.outlook.com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 
15.1 .126] .35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:07:18  -0500 
Received:  from  BN6PR09CA0049.namprd09.prod.outlook.com  (2 603 : 10b6 : 404 : 7a : : 11 ) 
by  SA9PR09MB5149.namprd09.prod.outlook.com  (2 603 : 10b6 : 806 : 45 : : 14 )  with 
Microsoft  SMTP  Server  (version-TLSl_2 , 

cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3131.20;  Tue,  30  Jun 
2020  13:07:15  +0000 

Received:  from  DM2GCC01FT010 . eop-gccOl .prod. protection . outlook.com 
(2a01:lll:f400:7d01: : 201 )  by  BN6PR09CA0049.outlook.office365.com 
(2603:10b 6:4 04 :7a: :11 )  with  Microsoft  SMTP  Server  (version-TLSI _2 , 
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3153.20  via  Frontend 


Transport;  Tue,  30  Jun  2020  13:07:15  +0000 
Authentication-Results-Original :  spf  softfail  (sender  IP  is  1  62  .2.17 .184.79) 

smtp .mailfrpifiri®®dkeo'antyi,i„ gov;  cookcoiintyil.gov;  dkistinnOrie  (message  not 
signed)  header . d=none; cookcountyil . gov;  dmarc=fail  action=none 
header . f rom-eookcountyil . gov; 

Received-SPF:  SoftFail  (protection.outlook.com:  domain  of  transitioning 
cookcountyil.gov  discourages  use  of  162.217.184.79  as  permitted  sender) 

Received:  from  CCCASV02.CCOUNTY.com  (162.217.184.79)  by 
DM2GCC01FT010.mail.protection.outlook.com  (10.97.3.132)  with  Microsoft  SMTP 
Server  (version=TLSl_2,  cipher=TLS  1G0HE__RSA_WITH_AES_128_GCM_SHA256)  id 
15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:07:14  +0000 
Received:  from  CCCASV02.CCOUNTY.com  (10.124.40.40)  byCCCASV02.CCOUNTY.com 
(10.124.40.40)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher=TLS_ECD&l_RSA_WITI_AES_l28_GCM_SHA256)  id  15.1,1261.35;  Tue,  30  Jun 
2020  08:06:46  -0500 

Received:  from  GCC02-BL0-obe.outbound.protection.outlook.com  (10.124.186.250) 
by  CCCASV02.CCCUKTY.com  (10.124.40.40)  With  Microsoft  SMTP  Server 
(version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 
15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:06:46  -0500 
Received:  from  CS20RO9MB4491.namprdO9.prod.oUtlook.com  (2603 : 10b6 : 610 : 36 : : 19) 
by  CH2PR09MB4395.namprd09.prod.outlook.com  (2603 : 10b6 : 610 : 6d: : 18)  with 
Microsoft  SMTP  Server  (ve.rsion-TLSl_2 , 

cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3131.21;  Tue,  30  Jun 
2020  13:06:40  +0000 

Received:  from  CH2PR09MB4491.namprd09.prod.outlook.com 
(  [fe80 : : 54b4 : la30 : 151b : 810f ] )  by  CH2PR09MB4  4  91 . namprd09.prod.outlook.com 
( [fe80: :54b4:la30:151b:810f%5] )  with  mapi  id  15.20.3131  .027;  Tue,  30  Jun  2020 
13:06:40  +0000 

From:  "CCSO  Intel  (Sheriff)"  <CCSQ.INTEL8cookcountyil.gov> 

Subject:  Pass  Through  -  (U//F0U0)  Criminal  Hackers  Target  US  Law  Enforcement 
Data 

Thread-Topic®  3tas$  Thrbugh  -  (U//F0UO)  Criminal  Hackers  Target  US  Law 
Enforcement  Data 

Thread-Index :  AdZGSZRVrVUDcf OlTiiWhSYEOiFXiAAj Zyaa 

Date:  Tue,  30  Jun  2020  13:06:39  +0000 
Message-ID: 

<CH2PR0 9MB4491 8DBCA1539- 41 8B6FB1 7FF56F08CH2PR09MB4491 . namprcO 9 .prod . outlook . com> 
References:  <LYRIS-103 90 995 6-14 1184 6-2020 . 06 . 29-15 . 13 . 38— isp-les- 
r.orth#!  ists  .  Illinois . gcv@l  ists .  illinois  .  gov> 

In-Reply-To :  <LYRIS-103909956-141184 6-2020 . 06 . 29-15 . 13 . 38— isp-les- 
:hOrth#lists . illinois .gov01ists , illinois . gov> 

Accept-Language :  en-US 
Content-Language:  en-US 
X-MS-Has-Attach :  yes 
X-MS-TNEF-Cor relator : 

Authentication-Results-Original :  cookcountyil. gov;  dkim^nope  (message  not 
signed)  header . d=none; cookcountyil . gov;  dmarc=none  action=none 
header .  f  rom •-eookcountyi.  1 .  gov; 
x-originating-ip:  [162.217.184.194] 
x-ms-publictraf f ictype :  Email 
X-MS-0ffice3  65-Filtering— HT :  Tenant 

X-MS-Of f ice3 65-Filter ing-Correlation-Id:  2f 90e5b8-3559-4ca4-557d-08d81cfb29b7 
x-ms-traf fictypediagnostic: 

CH2.PR0 9MB 4  395:  |  SA9PR09MB5149  :  |  MW2PR0901MB3689  :  |  SA9PR09MB4784  :  |  MN2PR09MB5003  :  |  DM6?' 
R09MB5863: | BY5PR09MB4929 : | BYAPR09MB3304 : | DM6PR09MB5192 : 
x-ms-oob-tlc-oobclassif iers : 

0LM: 9508 ;0LM: 9508;OLM: 9508;OLM: 9508;OLM: 9508;OLM: 9508;OLM: 9508;OLM: 9508;OLM: 9508; 
X-Microsof  t-Ahtispam-Untrusted?:  BCL :  0; 

X-Microsoft-Antispam-Mes sage- Inf o-Original : 

UrTnnB2hFcBuldWG/WlQW6SHaLsIud5b60myHpz6ITbVUSDZApWbWHRlBxrq5S5dDLfMQz21xkkKhXS5HG6af kS 
QTO j  Nbf Lpl  j;ydbEoLeu3hf CPnmlO / 0  7  xKsMLsD6S+idV/ J5$XSEt2phgXXdGCu JSbor JQvuHM3  30  f smLOdsFhyR 
8BTnhj  Ypu9DwUkY2 j  eDxiuP/ +Kcs2gf TgS5woIvA4kHUGZDLPluCCotuOoepg85MUZui6PMlZZwjh4ZyU5rNJ9c 
fBqeNVPc4TqSQNfhhiyaEI'8NR55N591IDhA+v8ZW3SldAtvxNvpYF5f fMVOK9FMws JSxfE Jf z8gmgh8f 9OQo0gfc 
Oa+ZoWOXOFAONtg= 

X-Fore f ron,t-Ant i spam-Report-Untrus ted :  CIP: 255.255.255 .25 5 ; CTRY : ; LANG : en ; SCL : - 
1 ;  SRV : ;  IPV :  NT,  I  ;  SFV :  SKI ;  H :  CH2PR0  9MB4  4  91 .  namprdO  9  .  prod .  outlook.  com;  PTR: ;  CAT :  NONE; ;  SFTY : ;  SF 
S : ; DIR: INB; SFP : ; 


x-ms -exchange -ant ispam-messagedata : 

3y/sGpBlWvBTdbJSe/KLUQQiBBZs5goYawJu81cTzjgw01fgwrUlWPtWZoS4FoBDi3DMVAIdIdfpuokXWFzcRCl 
JH/HHdN'annes6I,Jcm7?',BQ:<KY8nTqupiaZ0QcHYn32VhgHbnfEfKk3J0njiTBXF/.gB'I,0do Tw2VXQy80co6WjWs  In 
giNlEhXH2o98Mi+ JBaiqQIK2x6FdAfOJw/H3l3sgfdVGVSh6E j  UvOBOMY4U9dYWWMgHYlEUenZNbwXkSkV21i9m 
+yQ60eqyigBdds7  J7kDN+ndxJb/wU9mqRF3M8AtEAVqDvVKSOQPr5hSinZc0zg:uj,ltMclbvEaebrBq4  9 JsylvrCD 
7 f HUY/ G2yp2  4EPQ4V/wsCq5vlAMX7KTvyZf rOk6zFeil2rAOo j  4Hs+u+Whzr7 lHXAsNe J0khbdVT/7E+lM0HAzn 
v2Ch3FlzZul/WN4MhDWeoXf/syfwzoWMnN5bckNXHOvxkITX8Mtagt/yWvCGWllA/quBeMFR8hdVd 
x-ms-exchange-transport-f orked :  True 

x-ms-exchange-transport-crosstenantheaders stamped:  CH2PR09MB4395 
x-organizatioHiieaderspre served:  CH2PR09MB4395 . namprd09 .prod. out!  ook . com 
x-crosspremisesheadersf iltered:  CCCASV02 . CCOUNTY . com 
Content-Type :  multi  part /irri  xed; 

boundary="_004_CH2PR09MB44918DBCA1539E418B6FB17FF56F0CH2PR09MB4491namp_" 

MI  ME- Vers ion:  1.0 

X-CrossPremisesHeadersFilteredBySendConnectbr :  CCCASV02 . CCOUNTY . com 
X-OrganizationHeadersPreserved :  CCCASV02 . CCOUNTY . com 
To:  Oxidise!  osed  recipients :  ; 

Return-Path :  CCSO . INTEL@cookcountyil . gov 
X-SOpAt  t  r  ibu  t  e  dMe  s  s  age :  7 

X-MS-Exchange-Transport-CrossTenantHeaders Stripped:  DM2GCC01FT010 . eop- 
gccOl .prod. protection . outlook.com 

X-Foref ront-Antispam-Report-Qftfctusted:.  Cl? :  1 62  .-21  7 . 184 . 7.9 ;CTRY :US;  LANG:en;  SCI. : - 
1 ; SRV : ; IPV: CAL; SFV: SKN; H : CCCASV02 . CCOUNTY . com; PTR: Inf oDomainNonexistent ; CAT : NONE; SFTY : ; 
SFS :  (109986005)  (21480400003)  (166002)  (356005)  (19627405001)  (52536014)  (9686003)  (26005)  (550 
16002)  (33656002)  (82310400002)  (86362001)  (83080400001)  (81166007)  (28085005)  (186003)  (347560 
04)  (7416002)  (45080400002)  (8936002)  (8676002)  (336012)  (7696005)  (6506007)  (450100002)  (833804 
00001)  (5660300002)  (1096003 );  DIR:  INB;  SI*P : ; 

X-MS-Off ice3 65-Filter ing-Correlation-Id-Prvs :  384457b9-30d9-490c-d838-08d81cf 66e05 
X-Mi  crosoft-Anti  spam-Untrusted  :•  BCL :  0; 

X-Microsoft-Antispam-Message-Info-Original :  =?us- 

ascii?Q?oUdt+OMUlgpRe7Kl6gL18Ci|iiChvdsZbi7/3etWxt  JQwEHcj:a6v0Lowhtl|i<8n?= 

=?us -ascii ?Q?lgJ4UHL89KtlCbeq5UhQ8y9fWQddslQf+Z+NYvq703Q6E0y4 to j  S4TkGAdpu?= 

=  ?us-ascii?Q?Pkro+hCzW+yf 8ykeja3qMohGcxBkgYNpneaVmJpFyMoWOLiG/6NOH6M7  6mNQ?= 
=?US-ascii?Q?0Rlp3SZZyqyfsrJbphJrvDm0Dph97GJIh8zrT7/3NQlCwX5Ej42qgPr431+xX?= 
=?us-ascii?Q?wYC7Ni41g6BNAu5zmAvUFoIOat7N8ty8642sdtRJGkk6/VuHOOVdW4t82Eg6?= 
=?us-ascii?Q?5SRoF9MD8hNImj  jMlOMsBBzcvTtrqhCpyjBf  J6fdhtpGhlAf  8RXv5RQ:hZ0tAj  ?= 
=?us-ascii?Q?wrgfCGN7el  jif /‘6nE'j^  6FLYr7cSoiiVHt+3JX6ncdlZu2.9I3US7TP:EopkbRX?~ 
=?us-ascii?Q?gqcNmR2Zkl J2HWULNzaVXPgOZEdkEcZObJba7NSrQRv978hOaAqNr4pC6Mow?= 
=?US-ascii?Q?uRbldeC8c0sMJAvmXIQPeAnM3fvT/vr40g42R’yxf4Qa/99P589FtlR81wRbb?= 
=?us-ascii?Q?DC/HgQVwaX00qvlOnUkyNpwhNvT9qo0ZpZ065fV8AL/x2nhd+eC8XAsnHXEi?= 
=?us-ascii?Q?9O4xWnVy2QqAgaiOKAf6bfANJxRu0giliqwgbTT|fePfYKRlGgh/i|SYtse85Qu?- 
=?us-ascii?Q?U7h4hKDr924vwZwc2tt6sXB55XJ91 JvMX4Be3AlYavSFB03pAeYuoAQmZSVg?= 
=?us-ascii?Q?fwl7uNqpLTCftV6SvtykHHQNBYk3T3Fd+DxvEMWQNLq/vB2DKXM9jzc63Ceo?= 
=?US-ascii?Q?8  j  fMxccNMXl  l.lIgzNoV8LUqQac5r.55R6Y3'i  I  aE;wYRbVkkdJW8eY/Of  7voh75-?- 
=?us-ascii?Q?Ad+bPJTV0AcbBJZiVc62b8LDMAugPMtcCVB4t8P402QZbEAG31qiY/sAbTwZ?= 
=?us-aScii?Q?xerSjCi.ZrYCX/f  d91o+DSDr0/cIc4  5oMpSfbgQ2VJpwFj::OieJqzQbnPpEDxf  ?= 

=  ?us-ascii?Q?yIbCn7u8TIVj  7tfpvDaeP3RmVuN7IWp9OxWwHlZtvRu3AsPVT20 j IVuMhx5p?= 
=?us-ascii?Q?scnMj  qLmzBSwO6AXk8aJDSh+WC7Oxh0LIneCy87LClf AUlY60rglbKM14fbG?= 
=?us-ascii?Q?ffitS|llNe/T6wPIWpdbsw5DKxMattB:h4galhDuKTbOp8sptwGsHwS  JIY5QKKRg?= 
=?us-ascii?Q?sOLXCAJp5G135EpNfsfh+n/a4WATe40KSYK6c23nxnQ3FKzJF3ejuVBtKDYe?= 

=?us -ascii  ?Q?yIFCAvg3q^z:uYLTkWVXSOi3pwOgj  FsAsewu8KQ=3D«3D'?= 
X-MS-Exchange-Transport-CrossTenantHeadersStamped:  SA9PR09MB5149 
X-OrganizatidttiJeaders Preserved:  SA9PRQ9MB514  9  .  namprdO 9  .prod,  outlook .  com 
X-CrossPpemisesHeadersFiltered:  CCCASV02 .CCOUNTY.com 
X-CrossPremisesHeadersFilteredBySendConnector :  CCCASV01 . CCOUNTY . com 
X-OrganizatidnSeadersPreserved:  CCCASV01.CCOUNTY.com 

X-MS-Exchange-Transport-CrossTenantHeadersStripped:  DM2GCC01FT006 . eop- 
gccOl . prod. protect! on . outlook. com 

X-Foref ront-Antispam-Report-Untrusted:  CIP : 162 . 217 . 184 . 7 9; CTRY : US; LANG : en; SCL : - 
1 ; SRV : ; IPV : CAL ; SFV : SKN; H : CCCASV0 1 . CCOUNTY . com; PTR : Inf oDomainNonexistent ; CAT : NONE ; SFTY : ; 
SFS:  (86362001)  (33656002)  (166002)  (7696005)  (55016002)  (83380400001)  (19627405001)  (823104000 
02)  (26005)  (6506007)  (9686003)  (109986005)  (81166007)  (83080400001)  (5660300002)  (8676002)  (450 
80400002)  (8936002)  (336012)  (450100002)  (7416002)  (52536014)  (21480400003)  (1096003)  (186003)  ( 
28085005)  (34756004) ;DIR:INB;SFP:; 

X-MS-Office365-Filte»ipg-Correlation-Td-:Prys:  074aa61c-9bf 6-4913-1757-08d81cf 6823f 
X-Microsof  t-Antispam*|Jptrusted:f  3CL :  0; 


X-Microsoft-Antispam-Message-Info-Original :  =?us- 

ascii?Q?Q£tffekTPrlmz  J6BbC/ 30s  vKBf.nl/NO/tduopiS5vJOz6wz4UyD7  SO  OgSKZLUj?= 
~?us-ascii?Q?rhAKbzepbg8Yj;f  OrSZcOcuBn/QoL/HUpxwlUdvTdBVWarfQ  jgP^bG4K!lZ^issZ7;- 
=?us-ascii?Q?LnelQkUvsIeFmqvdoZ8iIuCW40Ruw0mQufWuk5SY113sx/o8htBZEx09hTE8?= 

=?us -ascii ?Q?vPfwldkBMT3vr j QKNdcGiQWX4EtTb8ziLhgWgvfMli/Rcc7M2Cy7zIwPaK4v7= 

=  ?us-ascii?Q?2LnHj  FhRcxB07  4NmneOC3YOIU9d2WFO+g21QnMRlafCpSfgRwLlUEtIQnVIV?= 
~?US-ascii?Q?zUcHiexjKNv+OY85IY+cIolNmWQlJtC0qOsoXFvMuMNeCG3mqF827BO4GxTC?“ 

=  ?us-ascii?Q?HrWbHgAU2DlEPKY+EXQz8Dy4w+9+4HVIdxDI j WC6w5iRhKwwct j  e j  4  +  llzTb?= 
=?us-ascii?Q?99SVR9hyY20/rH7r2TRtlfXeFmZLbxPBUPxSKvzWVzIJzNs41IvD8TnFpscb?= 
=?us-ascii?Q?HNrHaOK2X99063AD5r0AbMM6RN36P7eHtufGppXwluDRi6FYgZ7'riT5gRTHfYf= 
=?us-ascii?Q?jEtulSIWAHxxCuMq0LKwts0yXNJJQdQ4WvrHsx8OzfTdO7StBiTzML5rfm3A?= 
=?us-ascii?Q?VFxO+OJcEtMpgOrOu3.ji+d7t2Wj  j:ibRcD  /ZflRf  A/lB+lIphelbuKT of  9S8M2J?p?= 

=  ?us-ascii?Q?b2rk8uD0NrpsuohEuJTUQ6bKnWACtzbqLUMWOU3STIYWNO9pj  2PWhQOOUAhC?= 
=?us-ascii?Q?rm5BJSf 7p6CSfiZeXFipZZnXOsMlqMbuL09eGMC2LA33W5f /RV7S JUilHwekz-f^' 
=?us-ascii?Q?0M2/NAAFlW9uMwoQxVphCeGiVaynPkpamb4PAY6F0sW8rg/SXSKm61Do5HejW 
=?us-ascii?Q?e6qqr87pQAsUTTuFAJNbicdE6ZwtvTv6W41G0XE6dJNCm7m8PrWy9aZsxLFg?= 

■  ?us-asci  i?0?8ssqz/.2YUX52HjR6D5YDUw43mpAePgvzaKYyg4  PmynwYI  oaJ61  cfN2MRR5oA? 
=?us-ascii?Q?6+9O9dv/CEIKD4p8ZsQL0ZMXraJkbTMam/7tMNw+YMCKgHI/JnULTuFxHBuI?= 
=?us-ascii?Q?UYn9ziU9cbRsOXWpOWeyXraXIC8e2nJ3uc8TMwJUDORdQTpkK/Q4i®E7'lP6  J?c= 
=?US-ascii?Q?ydYxxJB0zdiHmjO44EpGv0ywzp3Re/q5Tlv6aato2wz81Y7izsOz6BUNbU4r?= 

=  ?us-ascii?Q?DItW05VQ+S0ZlF9e j  SZY6QbbJlods7kN7CaTX+w0dooYAfLLBEcMpEMxLTHB?= 
=?us-asGii?Q?m6PkFxzpcBStQG509PKjKGSWX5oLlW7TC7Ggsfli=3:&=3fiP= 
X-MS-Exchange-Transport-CrossTenantHeadersStamped:  MW2PR0901MB3689 
X-Orgard  zar ion Headers  Preserved :  MW2PR09Q1MB3689 . namprdO 9 .prod. outlook . com 
X-CrossPremisesHeadersFiltered:  CCCASV02 . CCOUNTY . com 
X-CrossPremisesHeadersFilteredBySendConnector :  CCCASV02 . CCOUNTY . com 
X-OrganizaticnHeaders Preserved :  CCCASV02 .CCOUNTY.com 

X-MS-Exchange-Transport-CrossTenantHeadersStripped:  DM2GCC01FT010 . eop- 
gccOl . prod . protectd  on . outlook.com 

X-Forefront-Antispam-Report-Untrusted:  CIP : 162 . 217 . 184 . 7 9; CTRY : US; LANG : en; SCL : - 
1 ;  SRV : ;  IPV :  CAL ;  SFV :  SKN ;  H :  CCCASV02  .  CCOUWfY .  com;  ETR nf  oDomainlfcnexi s tent ;  CAT :  NONE ;  SFTY : ; 
SFS :  (33656002)  (55016002)  (1096003)  (7416002)  (45080400002)  (34756004)  (8676002)  (28085005)  (26 
005)  (186003)  (21480400003)  (5660300002)  (19627405001)  (8936002)  (356005)  (86362001)  (6506007)  ( 
82310400002)  (336012)  (109986005)  (7696005)  (450100002)  (9686003)  (83080400001)  (81166007)  (833 
80400001)  (52536014)  ( 166002 ); DIR: INB; SFP : ; 

X-MS-Of fice365-Filte£ing-Correlation-Id-Prvs :  75d868a3-db35-4216-10aa-08d81cf 696d0 
X-Microsof t-Antispam^ttfitrustedr  3C1 : 0; 

X-Microsoft-Antispam-Message-Info-Original :  =?us- 

ascii?Q?9J2eilfACgVRnX99cJQ4EA2id2ez5PpCeC4/xysEMoK2n+170umL7WVDJR5?= 

=  ?us-ascii?Q?rlxODoxlplZygsRYfqb5bvLtl4d3935xgp+KmCt8rubV4wI12Y/E4  3Tmb3bj  ?= 
=?us-ascii?Q?llbAYtWDY4OI3Kg06dHfdJ7T4gqOshzX8d86bw0TliJlwpP19GapwYDRU0iJ/‘J^ 
=?us-ascii?Q?dkUBZHuKsnaOuCbOGMteCgWCzxWyfESg4yPilsOeG14yWYistrFSoe4ko3Lp?= 

=  ?us-ascii?Q?NKe02PXTX61EC4 j WNi3as07yGeBVDF+53tOrU12/W+9TO5Gj  4Cwq9z5m5YbD?= 

=?US-ascii?Q?Nli:YAnsnZp:XI5mrgi5/tjx5ycxy8FnGwJJ8SLDRcQnZ21sI  j  fbFj  Js  jlA6z8//>;fb; 

=  ?us-ascii?Q?DaJWqbuHAw2  6KpYVnonodRPJmhk3YknbyO JZNL5cx5Tu+zBlPKf 7+P/Q9gS?= 
=?Us-ascii?Q?WLQJ0/sjcMxYblj/ligbg2iXsY/4bAxDaqlIXX17p/Rf  jm9Y7’t;h8QSdcXKkOV?= 
=?us-ascii?Q?qP0surUPqUIy0XrUh44olBTSkTGIe4orz21n6hlukdT4PqakRtgxwyE3Q059?= 
=?us-aseii?Q?iBBmQi0LK0rURzz:lNQ5gtfmLv8QDNa3XKPfQaX+bkkcYUpFpVoU2enQYGi;k5?= 
=?us-ascii?Q?84D44TppipB:9Tluyed4p3Md5os8q+UpCylnCrlJuqHXtzjV2/18qV8ApQnp9?= 
=?us-ascii?Q?0UpyaZ9fYsCNB9NncJ4oX3D33YtI/GIcKJoQqq4N222/ipk9ZV+5FB130u6x?= 
=?us-ascii?Q?qlrdvikighUXmAPnkqDpMqQUZ:JiblpAzOOXc/23qIxNhY7Hal4etDVMPaL228?= 

=  ?us-ascii?Q?OMLaOkExuPYpfKrOFvE7Q9gctwrX4+BiPTTFgbpOAxSlKEOTlgz/ sglSvj  0r?= 
=?US-ascii?Q?wPHU++CaYxE4iyrRfrQ8T2Y6Nw8gogF3l8V9POlR4iFn630bziuWyg7bcbw3|t= 
=?US-ascii?Q?6RiaIrxERmO6yLzjzsaC8RADW5Ii8/10dOH¥PxFXmBCgcEDdSMse3XLBEjEV?fe 
=?us-ascii?Q?7K9800xunyhmFA3MrDMpcFVyf DdvSBFnsyONKPy6yQa23Zkx7N5YcRR/XrEY?= 
=?US-ascii?Q?YrKci8mMdkLPYdOuCT6dzmYS‘Z§fi4AtPvFkLy7gWLpPjMj;TMYxCbJQIKSsf 
=?us-ascii?Q?Rhkm5i30KB0VeKWrSaQf F/ 5CYLwuKVwKDq0bvhwp03WcIWI3wTt JpVzdF/ +A?= 
=?US-ascii?Q?0Ulz+AGBqDZkRQN8/PEzxR87do4hCeQ3C60t0GaeoL)|.liSw+,h:QFBs5Tl|J:SZm¥?= 
=?us-ascii?Q?ylOXNBQo3enwxhkRze+doWFXxBOyNplW19hVwg=3D=3D?= 
X-MS-Exchange-Transport-CrossTenantHeadersStamped:  SA9PR09MB4784 
X-OrganizationHeaders Preserved:  SA9PR09MB4784 . namprdO 9 .prod. outlook . com 
X-CrossPremisesHeadersFiltered:  CCCASV02 . CCOUNTY . com 
X-CrossPremisesHeadersFilteredBySendConnectoir:  CCCASV01 . CCOUNTY . com 
X-OrganizationHeadersPreserved:  CCCASV01 . CCOUNTY . com 

X-MS-Exchange-Transport-CrossTenantHeadersStripped:  DM2GCC01FT005 . eop- 
gccOl .prod. protection. .outlook. com 


X-Forefront-Antispam-Report-Untrusted:  CIP : 162 . 217 . 184 . 7 9; CTRY : US; LANG : en; SCL : - 
1 ;  SRV’i  l tW tCAL ;  SFV :  SKN ;  H :  CCCASVO 1 .  CCQUNf Y .  com;  RTtl : Inf  oDomainNonexi s tent ;  CAT : NONE ;  SFTY :  ; 
SFS :  (166002)  (28085005)  (81166007)  (336012)  (83080400001)  (19627405001)  (45080400002)  (5660300 
002)  (86362001)  (21480400003)  (52536014)  (33656002)  (6506007)  (450100002)  (26005)  (186003)  (8338 
0400001)  (34756004)  (9686003)  (8676002)  (82310400002)  (7416002)  (8936002)  (55016002)  (7696005)  ( 
1096003) (109986005) ; DIR: INB; SFP : ; 

X-MS-Of fice365-FilteKing'-GofrelatioTi^Td-i'SEVis:  fba07594-0eee-48c2-8215-08d81cf 6ac44 
X-Microsof t-Antispam-Untrusted :  BCL : 0 ; 

X-Microsoft-Antispam-Message-Info-Original :  =  ?us- 

ascii?Q?U6/abOYHvFUbfdPEmducHBvNxnh8Kj 0PZNteupvrpqeTxo2f  j.®YLVmMwZgwY?= 
=?us-ascii?Q?OWEW7no7FVh5kaGKvLe/+fYTedVj j z3PE/UxVlfUAYBql51b+ClwG08dy5 jB?= 

’•’?us-ascii  ?Q?KCI)hqRf4  I  238KaK"4l  wq2f  ykXF?0MuM4  wFYKvqk'l  c8  JUKI  AArYvbMUr.YqFk3z?  • 
=?us-ascii?Q?qPKRNvivlWxjTh7ubNwGi2VLbnje7vNNbSthVpVwu4Tmmk6MWOrF9+llnlSp?= 
=?US-ascii?Q?ZxfQWM++uisbi6mlQ2se+dgYXg7bLySv64bOJHW4C7kqDdO:Qj;  jD61j?B4Sclc!f>« 

=?us-ascii?Q?qmPJr3GPrdmf JPx90aSYcYREXzM6WrKRTGSc5dgjU+lFbEkgtkafS4CZaAXrfW 
=?us-ascii?Q?KKttEXpEBE/ThZbZGGuNPQmT+gO/j9vr56zEMpSWkVrkTk8KFTl/dT3iZTHI?= 
=?us-ascii?Q?  J8pAi/C/XXf  7ab;BI)t5UMECDrdKg2APepydHAVuuFTb2+brZrBd7hwyFC3x6A?= 
=?us-ascii?Q?wfCPOIGSXGXN67BzstdQBw42+FODvoA431DMJ5cMSBrAohLr5ildyMCXqKWU?= 
=?us-ascii?Q?3u4DqDostvPvOu5tpt82wNYglP5Dbjncq4WIXp8CsBwJsI JlLAJNzfXYMhlei? W 
=?us-ascii?Q?DVCqb/BriQlF+hWwkacCFHcwP8x0WpHhLUCi3+GSIr0polQKkzF2GATlqihqy- 
=  ?us-ascii?Q?CRw+r j  PIM/ G8CzwQICiIDkibj  9I+VCyIw21ToT3kNRLYjb2SUcJTe3mBoxYa?= 
=?us-ascii?Q?DC0Waa7DaAgEi4Q6 j  abFTalOiS15/Mj  srZlK3Cofvmj  c07XaUZ12mxKs  J  j  wi,?--: 

=  ?us-ascii?Q?aMIwdXVXQT3ucSZv8ug/ rLwgcQ2NqvmFLlBgj  j  70sKDypRt6mQ7G+5X8aTmA?= 
=?us-ascii?Q?7898+Ld/Zr/kuxs4  JWR10iwXlBOeC8SLWPPe+Ps0TZfmwtAcqN;h.SE9mdyCU5'¥::s 
=?us-ascii?Q?qL01IWorJWuYsDT5GqswjsTekEi+FE9GxP/FH3fnY8KmXlwoesP3Ssfvb775?= 

=  ?us-ascii?Q?uGi Jv6B/km7  3Fr6wLxj  YLf 2yC0AkbrWd9io7U/ xeD4+ToMmNa9PyBocOAYPW?= 
=?us-ascii?Q?kcGEN7eZwaEGtbXPwE7/08hPOfzdUhAbiqPiE0RH3rbLVh8gMRRLDif'Z:2ftxYA?= 
=?us-ascii?Q?bnCqtYeLClV/Q7xf JFy0u4kmlCgln6KOvSFrtUncW8zl6kR85t+4OK69uuLG?= 
=?us-ascii?Q?Dfl;i58328Pa8uf  DEkB25wfilyjbMEiryB:tJkSfYv27dRle03RJecqfkPapA,3tpyf>ti 
=?us-ascii?Q?15jBU0Fn9YiNjaIJRuX0/dmxTsmKknIEElNsTQ=3D=3D?= 
X-MS-Exchange-Transport-CrossTenantHeaders Stamped:  MN 2 PR 0 9MB 5 0 0 3 
X-OrganizatiqnBeaders Preserved:  MN2PR09MB5003 . namprdO 9 .prod. outlook . com 
X-CrossPremisesHeadersFiltered:  CCCASV02 . CCOUNTY . com 
X-CrpssPremisesHeadersFilteredBySendConnector i  CCCASV01 . CCOUNTY . com 
X-OrganizationHeadersPreserved:  CCCASV01 . CCOUNTY . com 

X-MS-Exchange-Transport-CrossTenantHeadersStripped:  DM2GCC01 FT007 . eop- 
gccO 1 . prod . protection*  outlook . com 

X-Forefront-Antispam-Report-Untrusted:  CIP : 162 . 217 . 184 . 7 9; CTRY : US; LANG : en; SCL : - 
1 ; SRV: ; lj?y;CAL; SFV: SKN; H : CCCASVO 1 . CCOUNTY . com; RT&t,  Inf  oDomainNonexi stent ; CAT : NONE; SFTY : ; 
SFS:  (82310400002)  (9686003)  (450100002)  (21480400003)  (83080400001)  (7416002)  (55016002)  (6506 
007)  (5660300002)  (45080400002)  (83380400001)  (52536014)  (33656002)  (109986005)  (336012)  (10960 
03)  (28085005)  (81166007)  (34756004)  (26005)  (166002)  (7696005)  (186003)  (8676002)  (8936002)  (196 
27405001) (86362001) ; DIR: INB; SFP : ; 

X-MS-Of fice365-Filtering— Correlation- I'd^Pfvs :  elbcl680-6c08-415c-lf 4f-08d81cf 6afee 
X-Microsof t-Antispam-Untrusted :  BCL : 0 ; 

X-Microsof  t-Ar.ti  spam-Mess age- Info-Original  :  =?us- 

ascii?Q?ztxSBFV52yZ/ j /LUyA0/2sKYbqvSuSKr4anXyJqGAezpsh7g7FreGXxsU21r?= 
=?us-aseii?Q?PxmlSVlcwMvBuM0KKbRXr5pwlVBPMkSV6WR9lAeFKdq4vFPqYH+KNKmy8Tq:e?= 
=?us-ascii?Q?tJqD2ZNiKWOCW4KtGdZqSMvT+m9mONftgl4x4kNwQWv97N/gD7h4rft.c2YkZ4?= 
=?us-ascii?Q?R2FbhlZTGHCZyqu3R48ZlighLCUkcllT7vLdNfIaxOgrSCeHsMwHpY95xxhg?= 
=?Us-ascii?Q?bZMEB3tGMmFIxY3XMDSkLdI+SaSFl54vj.SXvl+IW5zjc/KlWnYCVU2Hv7+jT?- 
=?us-ascii?Q?9R4D10WkdnXDZrcPktKZ08zoKsGC669zbVh666yP6saHF+FCwIBdwea+scdt?= 
=?US-asCii?Q?41v4HnaptblBqX19+ayEE!'Z973K06nxGf  tv9Nxf  c81Y6h4AmzzKgE3kpsSma/'fi:i= 
=?us-ascii?Q?yW39GlwtOrCZTaf st4Fw/dDfUS5AbNj  lq//x2Ff  7V7meuMQs6gchTOZGYAf  6?-- 
=  ?us-ascii?Q?olbluBRnllrwGpusTsX0Ah3SDh5kYcz JOiXOef 9VldVk+VMFrAVYj  Q7q2nOz?= 
=?US-ascii?Q?itGKtURd6BcsFwcZyaVUS8R3®/U+HVGwBJYLFb+LiEdQNkNTa+EUPUbdJflz?= 
=?us-ascii?Q?/KaCWvh2ecTJpUJLkjGtxA6cvxOyxnrcMlPZnEPy6NyqS889bpng07Ong/rq?= 
=?us-ascii?Q?cF16  jysmY:aSJg0s/XzwtIg7OBsitye7vc6MD6r,zUfit0QWgpvn7Q+NuFUzU5vi!= 

=  ?us-ascii?Q?UV6tl4UVimIm9 j Iyf if cUchhQa2n64  9PNBfefhL80qiAWnTNqW+xj  8vLp/BD?= 

=  ?us-ascii?Q?qbx3+2NixIC5RMpXDewXLizY5DSyUes421RmCWQAhj  suNmoYqi7ILmSuazM7  ?= 
=?Us-ascii?Q?WOC6WUwQwI8vdztOSNOKAbvf  kSsMZ7kR0wt3h&2/0ulC3uftE.lidinzrsZcC;UE‘f‘?=; 
=?us-ascii?Q?wolcYXfW3BoTFS4m25ZH53TymLdGEhqK2Cihvz8kvFEjMEB2rGqbADYuBgL/?= 
=?us-ascii?Q?RzoNxko4GXNcClcAbibEgRWGnfTiOK4/yGAOnvsWIIWxCYhAKHmu6KOzS9?= 

=  ?us-ascii?Q?o95BPRNBjxqef 8diGnvCvd6i4xWQg7ywyrLfqWClE9kMaj  8Z6XIo/UCpypJE?= 

■  ?us-ascii  ?Q?s5iXHCei  z.pz.rwOazYUk8c/8RL4EknCl /3aWwf  B  I  4Cqw2cYOYwVa  I  nvj  J.Zyjl,?- 
=?us-ascii?Q?pdR7nzmpe622VxhztmwXmxbTlTXfCTCXeu/qw2CJAw6/k/NQtG53XpL58XN9?= 
=?us-ascii?Q?nssil8iXy5adU9LHz/OtbKtt683yWQ4ieQpS/Q=3D=3D?= 


X-MS-Exchange-Transport-CrossTenantHeadersStamped:  DM6PR09MB5863 
X-Organizationlieaders  Preserved:  DM6PR09MB5863  .  r.a!nprd09  .prod  . outlook  .  com 
X-CrossPremisesHeadersFiltered:  CCCASV02 .CCOtfNTX.com 
X-CrossPremisesHeadersFilteredBySendConnector :  CCCASV02 . CCOUNTY . com 
X-Organizati©Jl}ieadersPreserved:  CCCASV02  . CCOUNTY .  com 

X-MS-Exchange-Transport-CrossTenantHeadersStripped:  DM2GCC01FT007 . eop- 
gccO 1 . prod . protection . outlook . com 

X-Forefront-Antispam-Report-Untrusted:  CIP : 162 . 217 . 184 . 7 9; CTRY : US; LANG : en; SCL : - 
1 ; SRV : ; IPV: CAL; SFV: SKN; H : CCCASV02 . CCOUNTY . com; PTR: Inf oDomainNonexistent ; CAT : NONE; SFTY : ; 
SFS :  (33656002)  (55016002)  (21480400003)  (336012)  (86362001)  (5660300002)  (8676002)  (8338040000 
1)  (52536014)  (45080400002)  (186003)  (7416002)  (450100002)  (19627405001)  (28085005)  (34756004)  ( 
9686003)  (166002)  (6506007)  (356005)  (109986005)  (26005)  (81166007)  (83080400001)  (7696005)  (893 
6002)  (1096003)  (82  3104  00002);DIR:INB;SFP:; 

X-MS-Of f ice365-Filtering-Correlatian-T,d~Prvs :  f 3d4eb42—  e293-453e-737 6-08d81cf 6d59e 
X-Mi crcsof c-Anti spam-Untrusted :  BCL : 0; 

X-Microsoft-Antispam-Message-Info-Original :  =?us- 

ascii?Q?2iQuMMGnrUWx6ax2DTAny/0Lk5uakcil+V4Sf8YzceiLryYKsHXfotMV0TYZ?= 

=  ?us-ascii?Q?Nf I+K4  53cbAUo7paLbsHbl/hNsYXqKgGuHKnRc0RaYTgBwNIdxQs/Y2OV2dj  ?= 
=?us-ascii?Q?bHGlVpwwjhl4CaDjNmRPryvcKaJ/yNlGwP2YywJEc9DIrl3 J0Vn7saHA7pjXt= 
=?us-ascii?Q?iTk5h.O+zwVubK8eCQcib6GWAq3RM9f  5ApkRxnli8ZloN9Mh6kybm9NOQClSltZ?= 
=?us-ascii?Q?GIQSrqKKIrxGXvfDAQmxyQr2I315heQE+EWZfq8YogTzeOJvthNI+/9Y/uoK?= 

■  Cus-asci i  ?Q?uG j  c4  /WMdqOz32AbrLkBnbWvl  sTHbxhHl  ZguxBk  j  9b z. Ka  R  7 R/.nmG Y x  s  S  S  9d  N  ?  -  • 
=?us-ascii?Q?x2/HcS3Es/qLXx52KVHSdS74tRPChQ18bQJtSicwdWovr/OaA9A79tINqcix?= 
=?us-ascii?Q?Zhbj+0Wn/b5RrPMiE+SC0kqlefuGoJLBV6KfTlH40xFFU+L7UyCh7FTo3UQN?= 
=?us-ascii?Q?5LZ4KQyB6Lqlhjm8hwPYoaWJ0KHitcBDeYMef 7QF8G2BX4SwUPgwT0L4hk4U?= 
=?us-ascii?Q?yueEOwTICaazHUOuv39pYfmGuefQlEOzSDBKRhNAECJyDHZWpDogXsK6kYWU?= 
=?us-ascii?Q?825SAzVmNoGNs5J6YY3WtkYV+4CWzL07UcyjHviiHz9Gl8ificJhz5dx+W5FQY?- 
=?us-ascii?Q?B6AmRVa/HdrL20WSci2HgeubEXqS6CURAhucGi0Ef 2aiTEtz40aDHsAP92M5?= 
=?us-ascii?Q?sF6wiMbYB5EDdCwfxD5H7cSfQ2SVLSexd4FcL9Qlf iOLj vyrH35z+uhAMUJy?= 

=  ?us-ascii?Q?69Mj  g8cIFLUxcmmwa9suXMAoIZXlCf 9YGQDpceCVtGnigPlk3vEhHkraN8FD?= 
=?us-ascii?Q?mUN  0Cn+lgubP4eMj lel06Vv3Xlrnd3xqLwtVl3Nx/2GFE8'qf/pgiFllu9Ryr?“ 
=?us-ascii?Q?+QkGj47yF9KY«J'ZlDR.ktJjD3cnsQiT3hVNRoZreRaM3pMjPai7BwsL8CzA+2Xy?— 
=?us-ascii?Q?GpDpg4WRR3NOPCCQFaE/9kOU37eQ08ClpWHhPjQKlTAoHulQRZMT8aLrR56?= 
=?US-ascii?Q?ufwPOA6LgZGeYmcWOwmlNE7w4i  jiiAAuU41ppLxoQUobVfyili/0mdmSta0MvTD?= 
=?us-ascii?Q?rLWflFroFDVX16SGmBfOZQixR9vDt90/ecuNlFNC4mVD0wlAB/tvQLFFWIyN?= 
=?US-ascii?Q?wwwQDqubPiJkUkh+ JMxxYMblRXkWCEh/fmZrYyiHkk/gnOPeKFv/YlluotlL?^- 

■  :?us-asci  i  ?Q?6vKf  AZWgsKl)9RTl  f  6ek8k  I  3 El  a?Icw6b8k54a6Q-  3D-3D? 
X-MS-Exchange-Transport-CrossTenantHeadersStamped:  BY5PR09MB4929 
X-Organi.z.ar  i  on  Headers  Preserved  :•  BY5PR09MB4  92  9.  r.amprd09  .prod  .  outlook  .  com 
X-CrossPremisesHeadersFiltered:  CCCASV02 . CCOUNTY . com 

X-Cross PremisesHeadersFil teredBySendConnector :  CCCASV02 . CCOUNTY . com 
X-OrganizationHeadersPreserved:  CCCASV02 . CCOUNTY . com 

X-MS-Exchange-Transport-CrossTenantHeadersStripped:  DM2GCC01FT005 . eop- 
gccOl .prod. protection, ■outlook. com 

X-Forefront-Antispam-Report-Untrusted:  CIP : 162 . 217 . 184 . 7 9; CTRY : US; LANG : en; SCL : - 
1 ; SRV: ; Iff: CAL; SFV: SKN; H : CCCASV02 . CCOUNTY . com; PTR:lnf oDomainNonexistent; CAT : NONE; SFTY : ; 
SFS:  (83080400001)  (109986005)  (82310400002)  (356005)  (7696005)  (8676002)  (166002)  (19627405001 
)  (21480400003)  (83380400001)  (81166007)  (1096003)  (8936002)  (9686003)  (28085005)  (450100002)  (4 
5080400002)  (34756004)  (86362001)  (7416002)  (33656002)  (52536014)  (186003)  (55016002)  (6506007) 
(5660300002)  (26005)  (336012);DIR:INB;SFP:; 

X-MS-Of f ice 3 65-Filt:esin9~CorrelatibU-Xd-Srvs :  5ed7fee9-80cl-4  310-9al9-08d81cf 8f 62b 

X-Microsof t-Antispam-Untrusted :  BCL : 0 ; 

X-Microsof t-Antispam-Message— Info-Original :  =?us- 

ascii?Q?DuNLeHlGGVjPNKsYCtFRqlcuHFwsd3Byk8iwd6UxmE72EdJBz/yaklCBwoTn?= 

=  ?us-ascii?Q?4us50xbj  Y4NwPOIxvQUrWSCBZGiU+ZhVNYlmJd9aOaWOZgdakMPTY6S6FR4  9?= 
=?US-ascii?Q?xHw0f s/pTD5EwMJDdP91MesF7 iwUYuLj  8FgYOgUMQMIH5vdlDYkw7q7 JNFf 8?= 
=?us-ascii?Q?naGDquZGorOxPUNj v+y7SfbKrO JXcfqFl/LW4fYkxqVsuYLwaUdfCLtY9XS5?= 
=?us-ascii?Q?mTl+yBJP81Jgrd7EadTfUNpxTbNJkX23HkMhj  JX/XBXsllWt/VFqmWHPN917;|Cf- 
=?us-ascii?Q?ziMEcwmj QvFJ23klQWvDkPugxzN6I14GLF14LeUdtZCdn46EB7SlVL77xSCU?= 
=?us-ascii?Q?E91/FD6Fs7L34aXlz94GlzUEz5rHd7ppwSSaTrDFttiixadzMXIQBqXRL0Gz?= 
=?Us-ascii?Q?8mRsCdsmbZz5FDSEAGkx7KUyUAxTVvlzLlLLS501ybZHm8WSc3+EuM7W+rC6?= 

=  ?us-ascii?Q? JfEvaf lzzYkBgrqnT/7pXzRoLrSGgDUV3d2fx4  99cvALvk6Fmd58QmXS J8i J?= 
=?US-ascii?Q?rryLw8mVjbkWnGNVfFN/jfqtdJBHJluLSCFLaVDssO:rulIJ<lwOTV/eUzfx7aN3= 
=?us-ascii?Q?whV7+VHUrfUS+ncVdnYQnAnVpFLqt8yWb73XBTxRywNFlmOjitldH9EGoFZ7?= 
=?us-ascii?Q?pBpsVqtdvj  tZI6Qy8Y2Pomtf G8E j  82h/+f0FJ0JzcQQgXYNb+P«T3B6C0vfGs?= 
=?us-ascii?Q?v01TaHo7b0VqL4t3eZimGmkOh/ecURHtCIwnHlli),ifi.lQ3vBynTi5KvodG01O?~ 
=?us-ascii?Q?9UF4XP8AQtUuda6zAdAPQJ2DhZAehluQQtD5UpsEmzIlJDUhaC9nyPCjtd58?= 


=  ?us-ascii?Q?Gz9uOPAelS/PytyhcgzIeOhvlPTLW/8moDoxPH2HwwgCx6j  7aAGzLnGuZ0Nd?= 
=?US-ascii?Q?HvS+4ZmaaZXQjMSx+UE6'#y4TFuykybC4c71)OnPswlmD8yBXMKOJbWbVL8HB.f« 
=?us-ascii?Q?ofIxCE3tTtR+kulsTNSW7Hhc70tvlBZvNBFHT9JqiV5.rXWdHfSx+Pq62kplf« 
=?us-ascii?Q?4+ltOeFKkcZ+nxj IwoohpvPJRMuGUzblXi9tLp6ZFcWgT0pesBz42H69s2dV?= 
=?us-ascii?Q?U+nkPw2QNzaqFrMe/Fk5z/+JX67fAQKq0lXT(26o+RYswZN9£B+kAL/uxGv08f= 
=?us-ascii?Q?RWMHFXcyaGOw39byC3iVzcI8RjU29FLyZVJPkmi+6j2vURLvKH8YL+OCrG4/?= 
=?us-ascii?Q?BT8ipxxBetU8g4xdQCifeS+epInSFegamECRec§K3U=3J}?= 
X-MS-Exchange-Transport-CrossTenantHeadersStamped:  BYAPR09MB3304 
X-Organi z at ionHeaders Preserved:  BYAPR09MB3304 . namprd09.prod.outlook.com 
X-CrossPremisesHeadersFiltered:  CCCASV02 . CCOUNTY . com 
X-CrossPremisesHeadersFilteredBySendConnector :  CCCASV01 . CCOUNTY . com 
X-OrganizationiieadersPreserved:  CCCASV01 .CCOUNTY . com 

X-MS-Exchange-Transport-CrossTenantHeadersStripped:  CY1GCC01FT004 . eop- 
gccOl . prod . protection . out! ook . com 
X-Foref ront-Anti spam- Report : 

CIP:162.217.184.79; CTRY : US; LANG : en; SCL : - 

1 ; SRV-: iW : CAL ; SFV : SKN ; H : CCCASVO 1 . CCOUUTY .com; PTR r.Inf oDomainSdnbxi s tent; CAT : NONE ; SFTY :  ; 
SFS :  (6506007)  (109986005)  (7416002)  (186003)  (19627405001)  (82310400002)  (8676002)  (450100002) 
(1096003)  (8936002)  (7696005)  (26005)  (336012)  (34756004)  (55016002)  (45080400002)  (52536014)  (2. 
1480400003)  (28085005)  (86362001)  (166002)  (83380400001)  (83080400001)  (9686003)  (5660300002)  ( 
33656002)  (81166007) ; DIR: INB; SFP : ; 
x-MS-Of  f  ice3  eS-Filtebibg-Correlatipii^'Id^PEVs : 

lccef 7  5d-1188-4b00-6fcf-08d81cfbl387 
X-Mi crosof r-Anti spam:  BCL : 0 ; 

X-Microsoft-Antispam-Mes sage-info : 

=?us-ascii?Q?rY4asHruCvlB8MPnwlQ2K3Fp5mywOGMdYccK8gW+5DUWNELxWxLFVcwFEjOM?= 
=?us-aScii?Q?R8hmD0gVu5QRODbV3240rPcgBOlmkcJ60QL7Gf tBTXYQEfoPCgbKz JOMH64E?= 
=?us-ascii?Q?5gdgcoJtulq6DMTiQ7MoTfvPtsnP6yGi8vgvtDQxMu4avnUosLKP7iAPwH79?= 
=?us-ascii?Q?94CtPxpl2DEuvGT94GNYZh/+0lYhGOcd9r/Jv65KYMLNdWNyepF4yRiA/N/af~ 
=?us-ascii?Q?DzCrRn5dAjGy8coSPF9r0Zjor98X+2ENksm3p0htt4Ia8mFP7jQdDDi+Iv+6?= 

■  Cus-ascii  ?Q?uX:-,FW8z.uWc  I  GUoGI  dv7 Dar. 9r  OUB j Or. f KvkQT  I  M I  PFKLhulcXrodrRVlh  JwKC? 
=?US-ascii?Q?JiKF84q:8R6MqfNIZEbWZ9bwX¥Zz+kqwp6Xv3Ui+X2vmuG/FWUO+N7M/Qt+tzf» 

=  ?us-ascii?Q?cI/52nxGI2  9 JcppJce2H0NTe7Ic8mul71rZkP2  4RWbQyJmr4PWcMYTnBwSsa?= 
=?us-ascii?Q?XZsp81qSctaZPexij 0wBRYpvnK3sUcsoVSqbdxdHlTGBLreUAyvxQEErHckw?= 

=  ?us-ascii?Q?zR2ASchZwY19alw6 j  6FY93/ t7  06iFJ08+lwt+vCmIdmUAJKdeIL88kxicJlx?= 
=?US-ascii?Q?eM/+Kgbz+UmpITg8o6BLRYvYYCYjUaiUYSPaKf JXUhHpXE3tsLPg62ugCE0Yq?= 
=?US-ascii?Q?+wfqUj  noWLVJbdB3 j M30pLFigC4 zCza JSvXJOhVj Zl Aw5rqOwcq I  9 1 Na4 / I wK? 

=  ?us-ascii?Q?EGvk4cbSIcCWKPdJUvIf fgj  64fQzKM+KJ2ipKESwO j  f03ej  4DnTAeQSGrk71?= 
=?us-ascii?Q?o69icAU0gD/FKR2S18slDNQ3udqSst8GCf+SI/iUtxmGHLxnFRIMt0PNKbcw?= 
=?us-ascii?Q?tDCW20zGtZ4i+Vkvp36/CW/eWCsmX6OdWSWG3PZx8NddTbNizXvW/ncgSbBy?= 

=?us -ascii ?Q?HPbbD20L4fVU4s+vwRoRTlAcdZwvPGfl0z9HMFjgT4NZjLlCspTtCXMq3sj  Spy?- 
=  ?us-ascii?Q?lTaulwz2G90wbcafVj  4XQj  zEHfbZ4qzptkC6ZFplplSI  +  lyAQC681+Pt j  eMu?= 
=?us-ascii?Q?/5ePGDEX89hMBJiKP9vauks57IzHAUCxhtoqCLvp+Assx8mcbWHcaaX83c5o?= 
=?US-ascii?Q?Wvh+pXW5DBw£XU«:U2xh:Rix4faZH5SQPAnyG35RIqslCNUZq4hgrahqrN6Zxx:'?i= 

=  ?us-ascii?Q?8vpVsSepJrT6fNikXSTwdIF3t J8TzOxKooKOWy6Crf Slo j  90SzuYRPRosmFO?= 
=?us-ascii?Q?t3/ulph8oAiNQN53dGpxQXkGNYEXevD5fLhML30b9te8uk4vd/Ipmlg95£|gD?= 
=?us-ascii?Q?SLGpjMMLKJGGWhSEnQZm?= 

X-Origir.atorOrg :  cookcountyi.1  .  gov 

X-MS-Exchange-CrossTenant-OriginalArrivalTime :  30  Juh  2020  13:40:33.4265 
(UTC) 

X-MS-Exchange-CrossTenant-Network-Message-Id:  2f 90e5b8-3559-4ca4-557d-08d81cfb29b7 
X-MS-Exchange-CrossTenant-Id:  8b4d55ae-6db4-4e05-a85c-59d6a256cd6e 

X-MS-Exchar.ge-CrossTer.ar.t-Ord  gi  r.al  AttributedTer.arroConnecting'ip:  Tenantld=8b4d55ae-6db4- 
4e05-a85c-59d6a2  56cd6e;-Ir=[162.217.184.7  9]  ; Hel«H CCCASVO  1 . CCOUNTY . com] 
X-MS-Exchange-CrossTenant-AuthSource : 

CY1GCCQ1FT004 . eop-gccOl . prod. protection „ outlook . com 
X-MS-Exchange-CrossTenant-AuthAs :  Anonymous 
X-MS-Exchange-CrossTenant-FroxnEntityHeader :  HybridQnPrem 
X-MS-Exchange-Transport-CrossTenantHeadersStamped:  DM6PR09MB5192 
X-Organi z at ionHeaders Preserved:  DM6PR09MB5192 . namprd09.prod.outlook.com 
X-CfOssPremisesHeadersFilteredByDsnGenerator : 

DM6PR09MB5192 .namprd09.prod.outlook.com 


Undeliverable:  Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law 
Enforcement  Data _ 


To:  Daniel.Moreci@cookcountyil.gov,  Darren.Makowski@cookcountyil.gov, 

Dennis.Nicpan@cookcountyil.gov,  James.Dillon@cookcountyil.gov, 
John.Hammond@cookcountyil.gov,  Joseph.Giunta@cookcountyil.gov, 
Leonard.Jagielski@cookcountyil.gov,  Miles.Cooperman@cookcountyil.gov, 
Patrick.Hecker@cookcountyil.gov,  Richard.OBrien1@cookcountyil.gov, 
Richard.Young2@cookcountyil.gov,  Joseph.Danzl@cookcountyil.gov, 
Zelda.Whittler@cookcountyil.gov,  Ricardo.Hardy@cookcountyil.gov, 
Wanda.Walker@cookcountyil.gov,  William.Mak@cookcountyil.gov, 
Alexander.Brodie@cookcountyil.gov,  Lisa.Farinella@cookcountyil.gov, 

Kevi  n .  G  raff  @cookco  u  nty  i  I  .gov,  Kevi  n  .Cooper@cookco  u  nty  i  I  .go  v, 
Kevin.Christofidis@cookcountyil.gov,  Kelly.Sweeney@cookcountyil.gov, 
Jonathan.Mobley@cookcountyil.gov,  John.Steed@cookcountyil.gov, 
John.Pradun@cookcountyil.gov,  Jeffrey.Pasqua@cookcountyil.gov, 
James.Scannell@cookcountyil.gov,  James.Hughes@cookcountyil.gov, 
Lissette.Rivera@cookcountyil.gov,  Giovanni.Veitkus@cookcountyil.gov, 
Gary.Newsom@cookcountyil.gov,  Frank.Caridei@cookcountyil.gov, 
Felix.Arvelo@cookcountyil.gov,  Diane.Haras@cookcountyil.gov, 
David.Delgado1@cookcountyil.gov,  Daniel.Strong@cookcountyil.gov, 
Daniel.Burke@cookcountyil.gov,  Cedric.Mccloud@cookcountyil.gov, 
Catherine.Domine@cookcountyil.gov,  Anthony.Burns@cookcountyil.gov, 
Gary.Rizzo@cookcountyil.gov,  Luis.Santoyo@cookcountyil.gov, 
Mary.Tamme@cookcountyil.gov,  Wanda.Barnes@cookcountyil.gov, 
Vincent.Gamez@cookcountyil.gov,  Thomas.Shader@cookcountyil.gov, 
Tangenise.Porter@cookcountyil.gov,  Tamara.Levickas@cookcountyil.gov, 
Samuel.Cory@cookcountyil.gov,  Ronald.Prohaska@cookcountyil.gov, 
Roger.Comer@cookcountyil.gov,  Robert.Waller@cookcountyil.gov, 

Robert. 0'Neiii@cookcountyil.gov,  Richard.Petersen@cookcountyil.gov, 
Rex.Knaperek@cookcountyil.gov,  Paul.Riley@cookcountyil.gov, 
Paul.Huss@cookcountyil.gov,  Nancy.Pavelka@cookcountyil.gov, 
Michael.Quan@cookcountyil.gov,  Michael.Gomez@cookcountyil.gov, 
Michael.Anton@cookcountyil.gov,  Maurice.Cernick@cookcountyil.gov, 
Matthew.Walsh@cookcountyil.gov,  Eric.Sellers@cookcountyil.gov 
June  30,  2020  8:40:36  AM  CDT 
June  30,  2020  8:40:38  AM  CDT 


Sent: 

Received: 


Undeliverable:  Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law 
Enforcement  Data 


From:  Microsoft  Outlook 

<MicrosoftExchange329e71ec88ae4615bbc36ab6ce41 109e@cookcounty.onmicrosoft.com 


To: 

Sent: 

Received: 

Attachments 


CCSO.INTEL@cookcountyil.gov,  Ricardo.Hardy@cookcountyil.gov, 
Wanda.Walker@cookcountyil.gov,  William.Mak@cookcountyil.gov 
June  30,  2020  8:55:34  AM  CDT 
June  30,  2020  8:55:35  AM  CDT 

Pass  Through  -  (U//F0U0)  Criminal  Hackers  Target  US  Law  Enforcement  Data 


CCCASV02.CCOUNTY.com  rejected  your  message  to  the  following  email  addresses: 

Ricardo.Hardv@cookcountvil.gov 

Something  went  wrong  and  your  message  couldn't  be  delivered.  This  could  be  a  temporary  issue. 
Try  resending  the  message  in  a  few  minutes.  If  that  doesn't  work,  forward  this  message  to  your 
email  admin. 

For  Email  Admins 

The  message  couldn't  be  delivered  because  a  mail  routing  loop  was  encountered.  This  may  be 
due  to  a  routing  misconfiguration  in  the  mail  flow  settings  for  either  your  organization  or  the 
recipient  organization.  If  mail  flow  settings  were  recently  updated,  this  error  may  be  temporary. 

Check  the  message  headers  in  the  section  below  to  determine  where  the  loop  may  be  occurring 
and  if  it's  something  you  or  the  email  admin  for  the  recipient  organization  can  fix. 

For  more  information,  see  Error  code  5.4.12  in  Exchange  Online  and  Office  365. 


CCCASV02.CCOUNTY.com  gave  this  error: 

SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 

<CH2PR09MB44919AB3DDCF48AlDC9A721BF56F0@CH2PR09MB4491.namprd09.prod.outlook.com> 

Wanda.Walker@cookcountvil.gov 

Something  went  wrong  and  your  message  couldn't  be  delivered.  This  could  be  a  temporary  issue. 
Try  resending  the  message  in  a  few  minutes.  If  that  doesn't  work,  forward  this  message  to  your 
email  admin. 

For  Email  Admins 

The  message  couldn't  be  delivered  because  a  mail  routing  loop  was  encountered.  This  may  be 
due  to  a  routing  misconfiguration  in  the  mail  flow  settings  for  either  your  organization  or  the 
recipient  organization.  If  mail  flow  settings  were  recently  updated,  this  error  may  be  temporary. 

Check  the  message  headers  in  the  section  below  to  determine  where  the  loop  may  be  occurring 
and  if  it's  something  you  or  the  email  admin  for  the  recipient  organization  can  fix. 

For  more  information,  see  Error  code  5.4.12  in  Exchange  Online  and  Office  365. 


CCCASV02.CCOUNTY.com  gave  this  error: 

SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 

<CH2PR09MB44919AB3DDCF48AlDC9A721BF56F0@CH2PR09MB4491.namprd09.prod.outlook.com> 


William.Mak@cookcountyil.gov 

Something  went  wrong  and  your  message  couldn't  be  delivered.  This  could  be  a  temporary  issue. 


Try  resending  the  message  in  a  few  minutes.  If  that  doesn't  work,  forward  this  message  to  your 
email  admin. 

For  Email  Admins 

The  message  couldn't  be  delivered  because  a  mail  routing  loop  was  encountered.  This  may  be 
due  to  a  routing  misconfiguration  in  the  mail  flow  settings  for  either  your  organization  or  the 
recipient  organization.  If  mail  flow  settings  were  recently  updated,  this  error  may  be  temporary. 

Check  the  message  headers  in  the  section  below  to  determine  where  the  loop  may  be  occurring 
and  if  it's  something  you  or  the  email  admin  for  the  recipient  organization  can  fix. 

For  more  information,  see  Error  code  5.4.12  in  Exchange  Online  and  Office  365. 


CCCASV02.CCOUNTY.com  gave  this  error: 

SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 

<CH2PR09MB44919AB3DDCF48AlDC9A721BF56F0@CH2PR09MB4491.namprd09.prod.outlook.com> 


Diagnostic  information  for  administrators: 

Generating  server:  DM6PR09MB5221.namprd09.prod.outlook.com 

Ricardo.Hardy@cookcountyil.gov 

CCCASV02.CCOUNTY.com 

Remote  Server  returned  '554  5.4.12  SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 
<CH2PR09MB44919AB3DDCF48AlDC9A721BF56F0@CH2PR09MB4491.namprd09.prod.outlook.com>' 

Wanda.Walker@cookcountyil.gov 

CCCASV02.CCOUNTY.com 

Remote  Server  returned  '554  5.4.12  SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 
<CH2PR09MB44919AB3DDCF48AlDC9A721BF56F0@CH2PR09MB4491.namprd09.prod.outlook.com>' 

William.Mak@cookcountyil.gov 

CCCASV02.CCOUNTY.com 

Remote  Server  returned  '554  5.4.12  SMTP;  Hop  count  exceeded  -  possible  mail  loop  detected  on  message  id 
<CH2PR09MB44919AB3DDCF48AlDC9A721BF56F0@CH2PR09MB4491.namprd09.prod.outlook.com>' 

Original  message  headers: 

Received:  from  BN6PR09CA0004.namprd09.prod.outlook.com  (2603 : 10b6 : 405 : : 14 )  by 
DM6PR09MB5221.namprd09.prod.outlook.com  (2603 : 10b6 : 5 : 265 : : 23)  with:  Microsoft 
SMTP  Server  (version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id 
15.20.3131.21;  Tue,  30  Jun  2020  13:55:33  +0000 
Received:  from  CY1GCC01FT006 . eop-gccOl .prod. protection . outlook.com 
(2a01:lll:f400:7d02: : 200)  by  BN6PR09CA0004.outlook.office365.com 
(2603:1 Ob 6:405: :14)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384)  id  15.20.3131.21  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:55:33  +0000 
Authentication-Results:  spf=softfail  (sender  IP  is  162.217.184.79) 
smtp .mailfrom=cookcountyil . gov;  cookcduntyil.gov;  ckim=none  (message  not 
signed)  header. d^none; cookcountyil.gov;  dmarc=fail  acticn=ncne 
header . f rom=cookcountyil . gov; 

Received-SPF:  SoftFail  (protection.outlook.com:  domain  of  transitioning 
cookcountyil.gov  discourages  use  of  162.217.184.79  as  permitted  sender) 
Received:  fromCCCASV01.CCOUNTY.com  (162.217.184.79)  by 


CYlGCC01FT006.mail.protection.outlook.com  (10.97.0.194)  with  Microsoft  SMTP 
Server  (versiotte=TI+Sl_2 ,  cipher«TLS_SC®fl&JRSA_WITH_AES_128_GCM_SHA256)  id 

15.20.3131.20  via  Frontend  Transport,;;  Tue,  30  Jun  2020  13:55:32  +0000 
Received:  from  CCCASV02.CCOUNTY.com  (10.124.40.40)  by  CCCASV01.CCOUNTY.com 

(10.124.40.39)  with  Microsoft  SMTP  Server  (versi:Q:h=TLSl  2, 

cipher=TLS_ECDHE_RSA_WITH_AES_12 8_GCM_SHA2 5 6 )  id  15.1.1261.35;  Tue,  30  Jun 
2020  08:55:08  -0500 

Received:  from  GCC02-DM3-obe.outbound.protection.outlook.com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(ver:sion-TLS1_2 ,  cipheuVL‘I.S_r;CDnH_RSA_W  ITH_AES_1  2  8_GCM_SHA2  5  6 )  id 

15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:55:08  -0500 
Received :  from  B  1,2 PRO 9CA0 0 3 8  .namprd09 . prod.Qutiook.com 
(2a01 : 111 : e400 : c743 : :48)  by  SN6PR09MB3151.namprd09.prod.outlook.com 
(2603  : 10b6 :  805  :  e5  : :  32 )  with  Microsoft  SMTP  Server  (version- ’TLS1_2 , 
cipher=TLS_ECDRE_RSA_WITI_lLES_256_GCM_SHA384)  id  15.20.3153.20;  Tue,  30  Jun 
2020  13:55:06  +0000 

Received:  from  CY1 GCC01 FT005 . eop-gccOI .prod. protection .outlook . com 
(2a01:lll:f400:7d02: :202)  by  BL2PR09CA0038.outlook.office365.com 
(2a01 : 111 : e400 : c743 : : 48 )  with  Microsoft  SMTP  Server  (version^TLSl  2,fi 
cipher=TLS_ECDRfe_RSAJWlTajSES_256_GCM_SHA384)  id  15.20.3131.21  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:55:06  +0000 
Authentication-Results-Original :  spf  softfail  (sender  IP  is  162.217.184.79) 
smtp ,mailfrom=cookcountyil . gov;  cookcountyil.gov;  dkim=none  (message  not 
signed)  header, d— none; cookcountyil.gov;  dmarc=fail  a'c t ipi+^n.Qn e 
header . f rom=cookcountyil . gov; 

Received-SPF:  SoftFail  (protection.outlook.com:  domain  of  transitioning 
cookcountyil.gov  discourages  use  of  162. 217. 184. 79  as  permitted  sender) 
Received:  from  CCCASV02.CCOUNTY.com  (162.217.184.79)  by 
CY1GCC01FT005 .mail .protection. outlook. com  (10.97.1.1)  with  Microsoft  SMTP 
Server  (version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 

15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:55:05  +0000 
Received:  from  CCCASV02 . CC0UNTY . com  (10.124.40.40)  byCCCASV02.CCOUNTY.com 

(10.124.40.40)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 

cipher=TLS  BCDRE_RSA_WITi_aBS_128_GCM_SHA256)  id  15.1.1261.35;  Tue,  30  Jun 
2020  08:39:57  -0500 

Received:  from  GCC02-Bl,0-obe . outbound. protect ion .out! cok . com  (10.124.186.250) 
by  CCCASVO 2 .CC0UKTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 

15.1 .1261 .35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:39:57  -0500 
Received:  from  MWHPR09CA0035.namprd09.prod.outlook.com  (2603 : 10b6 : 300 : 6d: : 21) 
by  MN2PR09MB5451.namprd09.prod.oUtlook.com  (2603:10b 6:208:21c:  :  1 2 )  with 
Microsoft  SMTP  Server  (version=TLSl_2 , 

cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3131.21;  Tue,  30  Jun 
2020  13:39:55  +0000 

Received:  from  DM2GCC01FT005 . eop-gccOI .prod. protection . outlook.com 
(2a01 : 11 1 : f 400 : 7d01: :200)  by  MWHPRO 9CA0 035 . outlook. offices 65 . com 
(2603 : 10b6 : 300 : 6d: : 21)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher=TLS_ECR8E_RSA_WITH_AES_256_GCM_SHA384)  id  15.20.3153.20  Via  Frontend 
Transport;  Tue,  30  Jun  .2020  13:39:55  +0000 
Authentication-Results-Original :  spf=softfail  (sender  IP  is  162.217.184.79) 
smtp .mailf roBs^dookcountyil. gov;  cookcountyll.gov;  dkim-^pone  (message  not 
signed)  header . d=none; cookcountyil . gov;  dmarc=fail  action=none 
header .  f  .rorm-coo  kcoun  tyi  1 .  gov; 

Received-SPF:  SoftFa.il  (protection.outlook.com:  domain  of  transitioning 
cookcountyil.gov  discourages  use  of  162.217.184.79  as  permitted  sender) 
Received:  fromCCCASV02.CC0UNTY.com  (162.217.184.79)  by 
DM2GCC01FT005.mail.protection.outlook.com  (10.97.3.0)  with  Microsoft  SMTP 
Server  (version=TLSl_2,  cipher=ThSJSC'DBE,_RSA_WITH__AES_128_GCM_SHA256)  id 

15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:39:55  +0000 
Received:  from  CCCASV02.CCOUNTY.com  (10.124.40.40)  by  CCCASV02.CCOUNTY.com 

(10.124.40.40)  with  Microsoft  SMTP  Server  (version=TLSl_2,/. 

cipher=TLS_ECDHE_RSA_WITH_AES_12 8_GCM_SHA2 5 6 )  id  15.1.1261.35;  Tue,  30  Jun 
■2020  08:24:46  -0500 

Received:  from  GCC02-BL0-obe.outbound.protection.outlook.com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  With  Microsoft  SMTP  Server 
(versi  on’-'TLS1_2 ,  cipher=ThS_ECBRE_RSAJWi#tl_AES_128_GCM_SHA256)  id 

15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:24:46  -0500 


Received:  from  MWHPR09CA0045.namprd09.prod.outlook.com  (2 603 : 10b6 : 300 : 6d : : 31 ) 
by  ByAPR09MB3128.namprd09.prod.outloOk.com  (2603:1  Ob 6:a03:a5: :10)  with 
Microsoft  SMTP'  Server  (version--TLSl_2 , 

cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384)  id  15.20.3131.24;  Tue,  30  Jun 
2020  13:24:42  +0000 

Received:  from  DM2GCC01FT007 . eop-gccOl .prod. protection . outlook.com 
(2aQl : 111 : f 400 : 7d01 : :205)  by  MWHPRO 9CA0 04  5. outlook .off ice3 65 . com 
(2603 : 10b6: 300 : 6d: : 31)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3131.21  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:24:42  +0000 
Authentication-Results-Original :  spf=softfail  (sender  IP  is  162.217.184.79) 
smtp .mailfrpw^ibpdkcountyil , gov;  cookcountyil , gov;  dfciki^hdft©  (message  not 
signed)  header . d=none; cookcountyil . gov;  dmarc=fail  action=none 
header . from  -cookcountyil . gov; 

Recei ved-SPF:  SoftFail  (protection, outlook. com:  domain  of  transitioning' 
cookcountyil.gov  discourages  use  of  162.217.184.79  as  permitted  sender) 
Received:  from  CCCASV02.CCCUNTY.com  (1  62.217.1  84.79)  by 
DM2GCC01FT007.mail.protection.outlook.com  (10.97.3.159)  with  Microsoft  SMTP 
Server  (version=TI,Sl_2,  cipher=TLS  KCDBF_R S a_WT t  h_aks_1  2 8_GCM_SHA2 5 6 )  id 
15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  1  3:24:41  1 0000 
Received:  from  CCCASV02.CCOUNTY.com  (10.124.40.40)  by  CCCASV02.CCOUNTY.com 
(10.124.40.40)  with  Microsoft  SMTP  Server  (versipn=Tl(Sl_2., 

cipher=TLS_ECDHE_RSA_WITH_AES_12 8_GCM_SHA2 5 6 )  id  15.1.1261.35;  Tue,  30  Jun 
2020  08:09:37  -0500 

Received:  from  GCC02-BL0-obe.outbound.protection.outlook.com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(versl  on- TI.S1_2 ,  cipher=ThS_ECDHE_RSA_Wl'®8_AES_128_GCM_SHA256)  id 
15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:09:37  -0500 
Received:  from  CY4PR09CA0093.namprd09.prod.oUtlook.com  (2603 : 10b6 : 903 : c7 : : 31 ) 
by  MN2PR09MB5515.namprd09.prod.outlook.com  (2603 : 10b6 : 208 : 211 : : 20)  with 
Microsoft  SMTP  Server  (versi  on--TLSl_2 , 

ciph@r“TLS_BGJ3HE_RSA_WITH  AES_256_GCM_SHA384 )  id  15.20 . 31 53.20;  Tue,  30  Jun 
2020  13:09:35  +0000 

Received:  from  DM2GCC01 FT007 .eop-gcc01.prod.protection.butlook.com 
(2a01:lll:f400:7d01: :201)  by  CY4PR09CA0093.outlook.office365.com 
(2603  : 10b6 :  903  :  c7  :  :  31 )  with  Microsoft  SMTP  Server  (version-  TI.S1_2 , 
cipher^TLS^BCDSE  RSA_WITH__AES_256_GCM_SHA384 )  id  15.20.3131 .23  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:09:35  +0000 
Authentication-Results-Origihal :  spf=softfail  (sender  IP  is  162.217.184.79) 
smtp ,mailfrom=cookcountyil . gov;  cookcountyil.gov;  dkim=none  (message  not 
signed),  header .  d— none ;  cookcountyil .  gov;  dmarc=f ail  actioh^ndne 
header . f rom=cookcountyil . gov; 

Received-SPF:  SoftFail  (protection.outlook.com:  domain  of  transitioning 
cookcounfeyil.gov  discourages  use  of  1 62. 2 17. 184. 79  as  permitted  sender) 
Received:  from  CCCASV01.CCOUNTY.com  (162.217.184.79)  by 
DM2GCC01 FT007 .mail .protection . outlook . com  (10.97.3.159)  with  Microsoft  SMTP 
Server  (version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 
15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:09:34  +0000 
Received:  fromCCCASV02.CCOUSTY.com  (10.124.40.40)  byCCCASV01.CCOUNTY.com 
(10.124.40.39)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher-TlS__EGBHE  RSA_WITH  AES_128_GCM_SHA256)  id  15.1 .1261 .35;  Tue,  30  Jun 
2020  08:08:49  -0500 

Received:  from  GCC02-BL0-obe . outbound . protection . eutl cok . com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (1  0.1  24 .40.40)  with  Microsoft  SMTP  Server 
(version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 
15.1.1261 .35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:08:49  -0500 
Received:  from  BL2PR09CA0028.namprd09.prod.outlook.com 
(2a01:lll:e400:c743: :38)  by  DM6PR09MB3081 . namprd09 . prod.outlook.com 
(2603 : 10b6 : 5 : 7b : : 25)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3131.20;  Tue,  30  Jun 
2020  13:08:46  +0000 

Received:  from  DM2GCC01FT005 . eop-gccOl .prod. protection . outlook.com 
(2a01 : 11 1 : f 400 : 7d01: :200)  by  BL2PR09CA0028 . outlook . of fice365 . com 
(2a01 : 111 : e400 : c743 : : 38)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher=*T'LS_EGBtli_RSA_WITH_AES_256_GCM_SHA384),  id  15.2.0.3131  .21  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:08:46  +0000 
Authentication-Results-Original :  spf=softfail  (sender  IP  is  162.217.184.79) 


smtp .mailfrom=cookcountyil . gov;  cookcountyil.gov;  dkim=none  (message  not 
signed)  header. d-none; eookcountyil.gov;  dmarc=fail  acbidh^Cdne 
header .  from--ccokcounty.il .  gov; 

Received-SPF:  SoftFail  (protection.outlook.com:  domain  of  transitioning 
cookeouhtyil.gov  discourages  use  of  1 62 .217 . 1 84 . 79  as  permitted  sender) 

Received:  from  CCCASV02.CCOUNTY.com  (162.217.184.79)  by 
DM2GCC01FT005 .mail .protection. outlook. com  (10.97.3.0)  with  Microsoft  SMTP 
Server  (version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 
15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:08:46  +0000 
Received:  fromCCCASV02.CCOUNSY.com  (10.124.40.40)  byCCCASV02.CCOUNTY.com 
(10.124.40.40)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
ciph£r-Tl.S_ECBEE  RSA_WITH  AES_128_GCM_SHA256)  Id  15,1.1261.35;  Tue,  30  Jun 
2020  08:08:11  -0500 

Received:  from  GCC02-DM3-obe . outbound .protection . out! cok . com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 
15.1.1261  .35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:08:11  -0500 
Received:  from  BN3PR09CA0052.namprd09.prod.outlook.com  (2603 : 10b6 : 400 : 3 : : 20) 
by  ByAPR09MB3237.namprd09.prOd.outlook.com  (2 603  : 1  0b6  :  a03  :  a2.:  :  22)  with 
Microsoft  SMTP  Server  (version- ’TJ,S1_2 , 

cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3131.24;  Tue,  30  Jun 
2020  13:08:06  +0000 

Received:  from  DM2GCC01FT009 . eop-gccOl .prod. protection . outlook.com 
(2a01:lll : f 400 : 7c01 : :202)  by  BN3PR09CA0052 . outlook. off ice3 65 . com 
(2603 : 10b6 : 400 : 3 : : 20)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3131.20  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:08:05  +0000 
Authentication-Results-Original :  spf=softfail  (sender  IP  is  162.217.184.79) 
smtp .mailf rom^bookcountyil , gov;  cookcQUntyil.gov;  dkift— h-phe  (message  not 
signed)  header . d=none; cookcountyil . gov;  dmarc=fail  action=none 
header .  from  ~cookcounty.il .  gov; 

Received-SPF:  SoftFail  (protection.outlook.com:  domain  of  transitioning 
cookcountyil.gov  discourages  use  of  162.217.184.79  as  permitted  sender) 

Received:  from  CCCASV02.CCOUNSY.com  (162  .-217 . 184 . 79)  by 
DM2GCC01FT009.mail.protection.outlook.com  (10.97.2.68)  with  Microsoft  SMTP 
Server  (versiorv=TUSl_2 ,  cipheri*TLS_EeEBE_RSA_WITH_AES_128_GCM_SHA25;6)  id 
15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:08:05  +0000 
Received:  from  CCCASV02.CCOUNTY.com  (10.124.40.40)  by  CCCASV02.CCOUNTY.com 
(10.124.40.40)  with  Microsoft  SMTP  Server  (version-d'LSl  2, 

cipher=TLS_ECDHE_RSA_WITH_AES_12 8_GCM_SHA2 5 6 )  id  15.1.1261.35;  Tue,  30  Jun 
2020  08:07:50  -0500 

Received:  from  GCC02-BL0-obe.outbound.protection.outlook.com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(version-  -TLS1_2 ,  ciphetHllS_ECDHE_RSA_Wi:SJi_AES_12 8_GCM_SHA2 56 )  id 
15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:07:50  -0500 
Received:  from  CB2lR09MB4491.namprd09.prod.outlook.com  (2603 : 10b6 : 610 : 36 : : 19) 
by  CH2PR09MB4395.namprd09.prod.outlook.com  (2603 : 10b6 : 610 : 6d: : 18)  with 
Microsoft  SMTP  -Server  (version- d'LSl  -2, 

cipher=TTS  ECBBE___RSA_WITH  AES_256_GCM_SHA384 ).  id  15.20.3131  .21;  Tue,  30  Jun 
2020  13:07:47  +0000 

Received:  from  CH2PR09MB4  4  91  .  r.amprc09  .  prod .  outlook .  com 
(  [fe80 : : 54b4 : la30 : 151b : 810f ] )  by  CH2PR09MB4  4  91 . namprd09.prod.outlook.com 
( [fe80: :54b4:1a30:151b:810f%5] )  with  mapi  id  15.20.3131 .027;  Tue,  30  Jun  2020 
13:07:47  +0000 

From:  "CCS0  Intel  (Sheriff)"  <CCS0 . INTEL@cookcountyil . gov> 

Subject:  Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement 
Data 

Thread-Topic::  Pass  Through  -  (U//F0U0)  Criminal  Hackers  Target  US  Law 

Enforcement  Data 

Thread-Index:  AdZOUZRVrVUDcf01TiiWh3YEOiFXiAAj ZyaaAAALg8I= 

Bate:  Tue,  30  Jun  2020  13:07:45  +0000 
Message-ID: 

<CH2PR09MB44919AB3BDCF48AlDC9A72iBF56F0@CH2PR09MB4491 .namprd09.prod.outiook.com> 
References:  CLYRIS-103 90 995 6-14 1184 6-2020 . 06 . 29-15 . 13 . 38--isp-les- 

north-0.1  ists  .  illinoi  s .  gov@li  sts  .  Illinois  .  gov>,  <CH2PR09MB44  918DBCA1539E41;8B6FB17FF56F0@CH 

2  PRO 9MB4  4  91 . namprdO  9 .prod , outlook . com> 


In-Reply-To : 

<CH2PR0 9MB4491 8D3CAX539-  41  8B6KBn  7FK56KO0CH2PRO 9MB4  4  91.namprd09.prod.o-atlook.com> 

Accept-Language :  en-US 

Content-Language:  en-US 

X-MS-Has-Attach :  yes 

X-MS-TNEF-Cor relator : 

Authentication-Results-Original :  cookcountyil, gov;  dkimpripne  (message  not 
signed)  header .  d=none;  cookcountyil .  gov;  dmarc=none  act,ion=none 
header . f rom=cookcountyil . gov; 
x-originating-ip:  [162.217.184.194] 
x-ms-publictraf f ictype :  Email 
X-MS-Office365-Filtering-HT:  Tenant 

X-MS-Of f ice3 65-Filter ing-Correlation-Id:  e59b4440-f289-4c42-0024-08d81cfd418d 
x-ms-traf figtypediagndstic: 

CH2PR09MB4395 :  | BYAPR09MB3237 :  | DM6PR09MB3081 :  | MN2PR09M3551 5 :  | BXAPHO  9MB3 128:  | MN2PR0 
9MB5451 : | SN6PR09MB3151 : | DM6PR09MB5221 : 
x-ms-oob-tlc-oobclassifiers : 

OLM: 9508 ;OLM: 9508;OLM: 9508;OLM: 9508;OLM: 9508;OLM: 9508;OLM: 9508;OLM: 9508; 
X-Microsoft-Ahtispam-Untrusted::  BCL:  0; 

X-Mi crosof  t-Ant.i spam-Message- I nfc-Originai : 

dorE2  6 j V2iSCAAZPeOVhoLD94Hv4kxz7P8odY90Qx9txS684f FRvsQrQNNuMcw5 j  3CXAvxwJ6RKVNhma4waBTSV 
NDGxp/cmBk.4RElmmOJLigUqP/p5XBKfbRyfc718XKcuXMUZI*lkV+zSCDOeo8miauinOJW7  JVM+LRl830Pl/aGzK0 
q6bOCroeqlaxlnk4eWaDTHoAOIyh54/JAVk4Vrimq/BMjI4mSCAvqOgQulCSA3SG/epzZtTashTb6dRWMQgeo+r 
JRKNCeaiFc3HMFzVIRVpFAf|:E6RE60VqdVOG2K5PsnuO/NhyqisQzWRtPZnKnQE65W6iRiiEbtgObqS5Zzmj cRR 
H4CGvuJF13tGlyM= 

X-Forefront-Antispam-Report-Untrusted:  CIP : 255 . 255 . 255 . 255 ; CTRY :; LANG : en; SCL : - 
1 ; SRV: ; IPV: NT. I ; SFV : SKI ; H : CH2PR0 9MB4  4  91 . namprdO  9 . prod . outlook . com; PTR: ; CAT : NONE ; SFTY : ; SF 
S : ; DIR: INB; SFP : ; 

x-ms-exchange-antispam-messagedata: 

lfyUdUNo6Rf 5kP/RudyGbEyoz+NqqBXdgwdr JdYqE14KGO77nPkGtTCiHAy0f TDHpKf au4FlsKcP4NPT jBZtOqo 

MOswESqf76XMqi53/H/ftP7B223MsFZ9fg5VOxHvc32BClwGPDW+JH3ilqP6YkWVZTuxClU|ify/m3qO/WA7zFrn 

qlHGYz/BQ9xQPFZN9ySyJCGd+j  9svK3 rmnh 7 n  j  YATQdwBhm/  L/ 0  6z. YBt kcQuXCphogmVS i- wxh.UeY s I)Q1  8 Z  9 J .ph  i 

UGfnt04ZLeJKhaQlTC86oFyonuAQ8DSt4ZyaYeVXcbN0uyrBFtWcyDVzIMi6RwmDU4aA8eX2yeHjnQlngAXfb6w 

xmTfCdhMIo3Kbla8ErnlLS56npY6/GW/CGnflqCGoLMKgNMBwrDrqOyAnvMuo6sEXA/bdkPEDSJD8JxHzl3yOp7 

4YkgohRwqBYld6GvNdDvRPJel2IzDacv+MFwLl jmdkuIxYJEykmLdGp8GhPL7  3qvrmFbfbAye08sP 

x-ms -exchange- transport-f or ked;  I' rue 

x-ms -exchange- transport-crosstenantheaders stamped:  CH2.PM-09MB4  395 
x-organi z at ionheaderspre served:  CH2PR09MB4395 . namprd09.prod.outlook.com 
x-crosspremisesheadersflltered:  CCCASV02 .CCOUNTY.com 
Content-Type:  multipart/mixed; 

bour.dary*:"_0  0  4_CH2PR0  9MB4  4  91 9AB3DDCF4  8A1DC9A72 1BF5  6K0CH2PR0  9MB4  4  91namp_" 

MIME -Version:  1.0 

X-CrossPremisesHeadersFilteredBySendConnector :  CCCASV02 . CCOUNTY . com 
X-OrganizationMeaders Preserved :  CCCASV02 . CCQUNTY.com 
To:  Undisclosed  recipients:; 

Seturn-Path:  CCSO . INTEL0 cookcountyil .gov 
X-EOPAttributedMessage :  6 

X-MS-Exchange-Transport-CrossTenant.HeadersS'tripped:  DM2GCC01FT009 .  eop- 
gccOl . prod. protection . outlook.com 

X-Forefront-Antispam-Report-Untrusted:  CIP : 162 . 217 . 184 . 7 9; CTRY : US; LANG : en; SCL : - 
1 ; SRV : ;  JPV : CAL ; SFV : SKN ; H : CCCASV02 , CCOUf TY .com; PT'R J nf oDomainKEonexi s tent ; CAT : NONE ; SFTY :  ; 
SFS :  (2940100002)  (34756004)  (356005)  (186003)  (86362001)  (109986005)  (166002)  (33656002)  (82310 
400002)  (336012)  (28085005)  (6506007)  (26005)  (45080400002)  (5660300002)  (450100002)  (9686003)  f 
83380400001)  (21480400003)  (81166007)  (7696005)  (83080400001)  (55016002)  (19627405001)  (525360 
14)  (1096003)  (8676002)  (8936002);DIR:INB;SFP:; 

X-MS-Of f ice 365 -Filtering-Correlation-ld-Prvs :  2b67f 42c-4bba-4f 30~216e-08d81cf 695cl 
X-Microsof t-Antispam-Untrusted :  BCL : 0 ; 

X-Mi crosof t-Ant i spam-Mess age- Inf c-Origi nal :  =?us- 

ascii?Q?ol+pBFwj 6bo8wgKCelMNaX0e9qCGT60pzLS+3l JjEwgEIIK+FAcNHrY14Ds+?= 

=  ?us-ascii?Q?YNSCw2Rqy/mzQmlCene7ak0YCR3BkbWuk6ZZ0 j  RyFoWv4kMSqIlvzfnkQUQ?= 
=?us-ascii?Q?E,lUq2CZP:2Th54  0cgSlCBlQLZiF6R613c7atUaESVNw5XdQYO58zbf  jU®2H4?= 

=  ?us-ascii?Q?D18IrN4ZXIVX/h8 j  DIf s+SQN8tdFhuoqGcI j WFIcwMSV8S16tHuz/ zqgFgeW?= 
=?US-ascii?Q?w6jtYH5RY8vF2OiROB9CNK7xz4h/b98E7ORi0T/wA6MAk3R£)Ws7YBLUeROQ?i 
=?us-ascii?Q?FPxluJTfOCr3wa34 JDDMmPjpSDYYMgBJWQi8 JkuVT04+gGAhSuDZK3Q+5z5r?= 
=?us-aScii?Q?uUs0GjQeJPicGBKB+rgKbyLP0AmdxZXy4YnpK07glga0m2r8qtSv6zzBzYCN?~ 

-  ?us-ascii ?Q?1 p/yoT 6  I J Jl /MREFDcrNpOWYi /MUSOJPStx5paF5dFvf 6F7E8V9l,ZvxXR4vn?- 
=  ?us-ascii?Q?G89zq2GHrKerSilY6Rhxtmmv9x7  8hhG992  4NThceYnAQPzZbs0EwVPAV2wvC?= 


=?us-ascii?Q?z4BG0b5CeTMDUeUWUHCC9212sMZ2nlwr2oWtGVpL6kFx4eMKJMZ Jt40dlb3r?= 

■  !?'js-ascii  ?Q?co4Vl  Qb  I  j YQmOAh/SWWI  7ZxUUcKyacG1  kbael  Cvl  rx7T,luxfcN8v4  I  HWj  4kh?-- 
•  Cus-asci  i  ?Q?7pM 11  KTk jmvOxf aSMpbu JVCe2B2cf gZg2pPKj  OcCS2pgc3UeOu5DTD3ezN7M?-' 
=?us-ascii?Q?AZ3wMLgFld7VdRXtHDaLIhOtReQwQlbx4ZHu6VZNvdoczkzMWSMKXLUmBtbJ?= 

=?us-ascii?Q?XY+VdbzeyrpN3EnpQZw+lFlw3AbeyPNfwaBfv+eUsfUtkWQ6FxUW8yawBnLu5r= 

=?us-ascii?Q?tlrSlFoUWWlkF0ax+HVC5fqluTvPgqGP7+PTi3k2dIyuADRkypQ+t20iT8PN?= 

~?us -ascii ?Q?ywBB3QwFNABqpiEEWT*JX4 PI 8TwAkT25GVYN0AQkTs3yMIq0aHpqaGFydXhkw?= 
=?us-ascii?Q?srnqFmT2A/lSFzuGMdDq+z8LSvbf JwlDihnCPlcrfLuRFgliUEhJcNXUXYf +?= 

=  7us-ascii?Q?iq6xP5/n57nf 9jqJ8q8EzzsQeSxzZOhhrhlmj leBQYvj rNBwHezXgj  t8/21M?= 
=?us-ascii?Q?cfFBBttkZbN/mtjKJw2rA19L8zOeLUaA+KNjRP:9sHaEqlkdIb}?,hggqGnWOOaW:S^ 

=  ?us-ascii?Q?2Zr6w7  zd3 J8xVOqXAc6Tf awVzcWE04K2LB91N2nlpPf klf 7cgJmK6vxaSGiD?= 

=?Us-ascii?Q?RXvVaUJV809oGpTW4tWurMNEVvB/J0/pFx/f9A=3D=3O'?= 
X-MS-Exchange-Transport-CrossTenantHeadersStamped:  BYAPR09MB3237 
X-OrganizatidSBeaders Preserved i  SYAPR09MB3237 . namprdO 9 .prod. outlook . com 
X-CrossPremisesHeadersFiltered:  CCCASV02 . CCOUNTY . com 
X-CrossPremisesHeadersFilteredBySendConnector :  CCCASV02 . CCOUNTY . com 
X-OrganizationiSeadersPreserved:  CCCASV02 .CCOUNTY.com 

X-MS-Exchange-Transport-CrossTenantHeadersStripped:  DM2GCC01FT005 . eop- 
gccOl  .prod. protection. ..outlook,  com 

X-Fcref ronr-Anci spam-Repcrt-Untrusced :  Cl? : 162 .217.184.79; CTRY :US; LANG: en; SCL : - 
1 ; SRV : ; IPV: CAL; SFV: SKN; H : CCCASV02 . CCOUNTY . com; PTR: Inf oDomainNonexistent ; CAT : NONE; SFTY : ; 
SFS :  (19627405001)  (7696005)  (8676002)  (33656002)  (8936002)  (1096003)  (6506007)  (52536014)  (4508 
0400002)  (81166007)  (83080400001)  (356005)  (86362001)  (83380400001)  (5660300002)  (166002)  (1099 
86005)  (450100002)  (26005)  (21480400003)  (9686003)  (186003)  (2940100002)  (28085005)  (34756004)  ( 
82310400002)  (336012)  (55016002);DIR:INB;SFP:; 

X-MS-Off ice3 65-Filter ing-Correlation-Id-Prvs :  9a0d0c34-aeal-42ee-el20-08d81cf 6a0c5 
X-Microsoft-Antispam*'l3&ti:usted;  BCL : 0; 

X-Microsoft-Antispam-Message-Info-Original :  =?us- 

ascii?Q?AxXaqsJllrC41 Js7f 71CuLtFSVA5AiGf sM/4P j j eg4DcMZU8ndOXxb2Nlp3bj  ?= 

=  ?us-ascii?Q?No6Xmk88kTXp/ imBMUPj  JywPliWQcP98McnPQRj CvcH8M8LOZFTmDqbYX/hs?= 
=?US-ascii?Q?8zVKhdd9WMltt3QCum3Sp7wadf  iU.kh.oldcq^iTWXvKx9YmFX7KuuSXDtDvJS?= 
=?us-ascii?Q?4Eg6e5rhl|iEyye/3«JVpoj:lVSezfR07UwzFTa8vQEoARL  JpUXseop61fgrlsg?“ 
=?us-ascii?Q?yZe+wgrersaBEKPCWq2xeIQox6o26fEMl+6Zw7Ibip4729/Qx841CU19Pbmf ?= 
=?US-ascii?Q?2ax5FAnw+XolmBosKI0Q95ywOO4NK4um7H3ub3ZmR9bVDOgo.q/h9ggy2bIZu?= 

=  ?us-ascii?Q?wj 10iVA7BLPf SOvlu4  9ppBG10Kx/Ne6SB3rlnBJ+YMboFAzyizqOLPzAj  Yx3?= 
=?us-ascii?Q?Z JTh5iurgm0cc9wDFbPVlsw0/AXP4udaXG8cnEtU87h8cMk8 JYBnUwe72  6cx?= 
=?US-ascii?Q?a+m8tZ3SBUPR4PlPVTsz/vca8qxkvxMA/ZYtoA71qaJabrN013vqQEvu/s2Q?= 

=  ?us-ascii?Q?lyLNHwA8H5d2XcHS0n6BLoky0dc/wlqyuvc4 JeQIn8KbY35unnqZtcloeUQ4  ?= 
=?us-ascii?Q?3phpeibifKAvj;.5pszMz5yZ30kqZtSALqd+I3DRWVdwfYQYMAWFkBDI4RSRY5'?- 
=?us-ascii?Q?A5fGS5rCwrh5iyeXvJG10Y54gR/Dy2A7KXZliV58IvfrDhqhX5qdh3/L8Lvw?= 
=?us-ascii?Q?Xxje5QJRKBx3r7W9plQS3iL7+2B/+mOLnREBtjIObOaRzC110GTL|S«^ZyfOY?= 

=  ?us-ascii?Q?o6bZTC9kdqBGokl06HCnC2weXlgpMdhRcbPgTsGwj  HdZru8DA/XP+/v9Tfdd?= 
=?us-ascii?Q?J25iTtnmqmfL4eKbuWtCvt7TiDIH7f5dJ2gJ6xve51hUWNPtW6UZKkbqaJG0?= 
=?US-ascii?Q?waduAT3^RDor3H788eW3SzL3W0yAj WI0kExk8SUdQLEgTkXqaHPcylroWmJ?= 
=?us-ascii?Q?8uusZMnpP2P7n0ZdhRlPqKn/+9iK3WkK3X4X95h6yylzaGdKnt82lMzyYkkK?= 
=?tis-ascii?Q?qtjHSjS8XBfhll 9 HN2M / q 8 j 0 o GMU g / a ONVuVC z i v wmU wmvM  ! 3 D ? = 
X-MS-Exchange-Transport-CrossTenantHeadersStamped:  DM6PR09MB3081 
X-OrganizatioHHeaders Preserved:  DM6PR09MB3081 .  r.amprc09  .prod  .  outlook  .  com 
X-CrossPremisesHeadersFiltered:  CCCASV02 .CCOUNTY.com 
X-CrossPremisesHeadersFilteredBySendConnector :  CCCASV01 . CCOUNTY . com 
X-OrganizationiieadersPreserved:  CCCASV01 .CCOUNTY.com 

X-MS-Exchange-Transport-CrossTenantHeadersStripped:  DM2GCC01FT007 . eop- 
gccOl . prod . protection . outlook . com 

X-Foref  £ ont-Antispam-Report-''0fe.tnusted:  CIP:  162 .217 . 184 . 7  9;  CTRY :US;  LANG: en;  SCL :.- 
1 ; SRV : ; IPV : CAL ; SFV : SKN; H : CCCASV0 1 . CCOUNTY . com; PTR : Inf oDomainNonexistent ; CAT : NONE ; SFTY : ; 
SFS:  (45080400002)  (450100002)  (83380400001)  (8676002)  (336012)  (33656002)  (7696005)  (830804000 
01)  (166002)  (82310400002)  (109986005)  (81166007)  (9686003)  (52536014)  (55016002)  (26005)  (29401 
00002)  (8936002)  (1096003)  (186003)  (86362001)  (5660300002)  (21480400003)  (19627405001)  (650600 
7) (34756004) (28085005);DIR:INB;SFP:; 

X-MS-Off ice3 65-Filter ing-Correlation-Id-Prvs :  ala96dea-0d08-4b55-38e4-08d81cf 6b8f 0 
X-Mi. cro s o f  t -  An c i spam-Un t ru s t ec :  3CL :  0; 

X-Microsoft-Antispam-Message-Info-Original :  =?us- 

ascii?Q?FvmXhdIytiUsOVSnN8NnqNql6Df lTTscTJCZOZOCHLg8IhK+vuRVhMQGKqIm?= 
=?us-ascii?Q?AGxKjMp5begrhrWxecRBipnDTn9xGGOZT6ccUf ZUKwxyrL3CxWcFdDgRCIuk?= 
=?US-aScii?Q?aW9VCeru9yvgD7  f  2dRTVaAnZhwgJ  f  ZA7TJ’JnkwK?XpKogOEUhGN‘jnQnukeYp? 
=?US-ascii?Q?CiN9xdG8TlxLjOLbS7eTqIMWfh8alblazzCESCrmHyykRXzQXUaKCcJlZYHP?= 
=?us-ascii?Q?QoxlOLqyvpRQSSczlIBZbZUP04EXUV70F660+rUWBHLfvoB3ALggbL70QTbS?= 


=?us-ascii?Q?cvX2juxiGmAtNrbvJXaZEW9DW7Nqu7LC4y9CbIDqSzeUd6Vn3+gS9eYDuUZ+?= 
=?us-ascii?Q?R9erPR909Hi6kaSaPUeGX8SiyfT6E7r  JElDIf  rheiFRERFd.7  j+TV2f  Iirip/ie?= 
=?us-ascii?Q?kXA8qmgwF:bK:£fZrzACXlABpqJZeWTjCwlUY/Wuv2CNfE0.WHEhiTiBdQ3nyox;.f« 

=  ?us-ascii?Q?MhRbr JFa4  37  3VPTIWwV4Nis4QZSLPWpXqw5ZYC2ss3VqdtMRPVg8CTp4Bf T7  ?= 
=?US-asciI?Q?JVp9KmTuavqypi41Q5wmrQr9ePF9N3m6pMtl3AB2rRBFZ'KqzOf9TNGYbSq5&f= 
=?us-ascii?Q?z9GyhLu/elWEmWLa3JB0cv0VAnsbu9PsSCKVp/uuQdQVLyFs9ufnGPt5Duw0?= 

■  -?us-ascii  ?O?81g5Rr)fDYbF5HZaNmz03nflRGnvcjkyLQpI,kV0S/.mQ7X6V\:9BYY5AplgCvQN3? 
=?us-ascii?Q?8HIT/OVkotFbnyiZymZLpjdnGHFNPnkiF8UzbgQoTAOeuNjr8XHZarR6XJHc?= 
=?us-ascii?Q? J6xlKPGfw55X8zGvJ0980xm/ Oj / CRO++1/ CpPxexTAsVj WWOZ6kwklQXOb2W?= 
=?us-ascii?Q?cd3xwG|£y3:vfy3JD2SAJnaFhGzmY6MCeA94TXZSxCIwlREDqF+4bbfEWYhQaQZJf?4 
=  ?us-ascii?Q?D/ 6AcNTkq+zbAetONj Ac0mZSRl62ZPFN7eLCCihTh7  0ohf 4  +  sBPN9dnbSE42  ?= 
=?us-ascii?Q?Vgs2cS13tOfX9a8hqe0H9NwHnD0grLPabsi9m8xe4ml03alT‘£r3oeO6L9G5S?= 
=?us-ascii?Q?zy005mee0yURkITE77MOvqQkATLr/zGdXzx5QKzv7McUW+HpFoan083sOmvC?= 
=?us-ascii?Q?fh/JsUbF4YaxEmQy/41sPY9BSlLpDftiIiaSaZVX9whXy7ViibsTJjV5BMwjXXb?= 
=?«s-aseii?Q?blb9MFRzmZkxZbAxlFwxQhbW42VHPJHk4wYSGwmcA2drYmj.LYKyLzNWCTTxa?= 
=?us-ascii?Q?V7yWn/rNQIZF801kApYQ3+QhQb4e0z+atnElGA=3D=3D?= 

X-MS-Exchange-Transport-CrossTenantHeaders Stamped:  MX2PR09MB551  5 
X-Organi z at ionHeaders Preserved:  MN2PR09MB5515 . namprd09.prod.outlook.com 
X-CrossPremisesHeadersFiltered:  CCCASV02 .CCOUUTY.com 
X-Cross  Premises  Headers  Fi.  Ire  red  BySendConr.ecrcr :  CCCASV02  .  CCOUNTY  .  com 
X-OrganizationHeadersPreserved :  CCCASV02 . CCOUNTY . com 

X-MS-Bxchange-Trar.sporr-CrossTer.ant  Headers  St  ri  pped :  DM2GCCG1FT007  .  eop- 
gccOl .prod. protection . outlook.com 

X-Foref  ront-Anti spam- Report— Distrusted:  CIP:  162 .217 .184.79;  CTRY :  US ;  I.AKG :  en ;  SCL :  - 
1 ; SRV : ; IPV: CAL; SFV: SKN; H : CCCASV02 . CCOUNTY . com; PTR: Inf oDomainNonexistent ; CAT : NONE; SFTY : ; 
SFS :  (2940100002)  (356005)  (34756004)  (186003)  (86362001)  (109986005)  (33656002)  (166002)  (82310 
400002)  (28085005)  (6506007)  (26005)  (5660300002)  (45080400002)  (336012)  (9686003)  (83380400001 
)  (21480400003)  (81166007)  (7696005)  (83080400001)  (55016002)  (8936002)  (19627405001)  (52536014 
)  (450100002)  (1096003)  (8676002);DIR:TN8;SFP:; 

X-MS-Off ice3 65-Filter ing-Correlation-Id-Prvs :  16cb9bf 7-f 919-499b-5664-08d81cf 6d5d7 
X-Mierosof t-Antispamr'Ubtrusted;  £©£»■:  0; 

X-Microsof t-Anr.i. spam-Mess age-inf o-Original  :  =?us- 

ascii?Q?VlZRMfnBquylm2uOtpqWcQf 3b7xgJ7H6xJ4A8IqglTLVEdBIhuph3n8z5f 9K?= 

=?US-asCii?Q?4naj  k5RqNK+qKuepSmZ052AlgXsGBftXyBkzdnvd4Dr  jLliljlt+atDewOVxIQsi'f* 
=?us-ascii?Q?8IggQ423t+ipbEVuRw3rIBhwoRDGEHmVv08SK10z7mNBPBbILvg3hXi2zf 71?= 
=?US-ascii?Q?y+mON7oqldds8pYLpe550sS0MzAJK4fHYnW/AmgCeEWuSawhFyWtmnDSaCFz?= 
=?US-ascii?Q?o04Dp3+/ jiPPz4k/iTwgj  9ZIxMFTj  t7/y2/ZH+UBRfRvo2g9hyKwAhGiePEgw?= 
=?us-ascii?Q?27cNrsf DlywAJvN3A+BHE6yisQm+9p8CnLIVnJcVzygvq6RA9tyEQhvewKtL?= 
=?us-ascii?Q?nlV0TrwG0yj  dckHmJceVKWiYdKUYqaw6PGb3 jLesMAvKnJ0c88iErS940d:ZO?= 
=?us-ascii?Q?USZhFrbMz5u0enVhkQ2y/NnbJkE0DuuvCqO7HOSf ZbvR355TpOI9Cpq2bGLT?= 

?us-ascii  ?Q? J0/?cXPxX/HdVTnTG4W5eSrr.UI)C9Fn  t  8H1  z. IS0nJPRSbnJA7  J3q)mI,of  0zK6? 
=?us-ascii?Q?HBuyDYRSvE6c46bj j CHM7ezLCPcj 9mBAXK7TSk6npxmMmFAN+5BU5khHWRh6?= 

=  ?us-ascii?Q?f 7I2XLe/V/FvXsqHVdYCdTr2  60itZPezhVCZzNiw38eifClkQ30XvGRCCEiY?= 
=?US-ascii?Q?a6hE5dSlIcW8hEmbbiVOistkSgOZAhiibb310d/y5Cj  Se4Pep8pbkSsqoxA4n?= 

=  ?us-ascii?Q?q33M/vp9oHoFGk4hE9IGIMNqrX0CapkHmvICdhTCs34 j  9w9FQQLWTE70BiUt?= 
=?us-ascii?Q?ubj30gTfcMCHkUNH9HMlgI7J5jUdSTytz61b4cLMrMjG5MBjeG2yl,jiiLGDmL?= 
=?us-ascii?Q?SGq6XipiRXXU/HPfIuN06k0Tnx8FQXhlKyi6RCg4oiyRppGv/lQK381OgXR/?= 
=?us-aseii?Q?o/WlYFhs5v/m8esrBcNTRqa50sPRCVr5oeN8+nD6YG04r7oVL+M3OhVfeOSM?= 
=?us-ascii?Q?dnD4R9J75LMM2JhFFShRjrmlPC3+:28eDirpr5c3jrKqwjMNgTUKSFpApfAGi?= 
=?us-ascii?Q?838+m2dTJFGIfedGXvK50K8TzQG7OyID/3spIKCd/qmyvLFNdVbdMtXYGNTw?= 

■  ’?us-asci  i  ?Q?g905  t  j  j  fdLPXqgzGbH  JWVezf  l)K60h  JKSL:8GI,V8qW  I  gl  OSJLf  r3/5S7  0H6Fak?- - 
=?us-ascii?Q?75b4Rza4WH7i2vg8pC4zSBS4aW5keW7RJyGQVA03BJlNi2v4FvMRo9C++wj /?= 
=?US-ascii?Q?tR5t3zUlOaO'lB0UlFGHgdR2BjEDwcNwNHvmLo59LmXRESl’a211tmgx9cSL3f|l=: 
=?us-ascii?Q?NXGcdeNG9PXe3iaUkiQy?= 

X-MS-Exchange-Transport-CrossTenantHeadersStamped:  BYAPR09MB3128 
X-Organizar ionHeaders Preserved ;  BYAPR09MB31 28 , namprdO 9 .prod. outlook. com 
X-CrossPremisesHeadersFiltered:  CCCASV02 . CCOUNTY . com 
X-CrossPremisesHeadersFilteredBySendConnector :  CCCASV02 . CCOUNTY . com 
X-OrganizationHeadersPreserved:  CCCASV02 . CCOUNTY . com 

X-MS-Exchange-Transport-CrossTenantHeadersStripped:  DM2GCC01FT005 . eop- 
gccOl . prod .protect! on . outlook , com 

X-Foref ront-Antispam-Report-Untrusted:  CIP : 162 . 217 . 184 . 7 9; CTRY : US; LANG : en; SCL : - 
1 ;  SRV:  ;•  IPV:  CAL;  SFV:  SKN;  H :  CCCASV02  .  CCOUNTY .  com;'PTR:rInf  oDomainNonexistent ;  CAT : NONE;  SFTY :  ; 
SFS:  (336012)  (82310400002)  (7696005)  (109986005)  (356005)  (86362001)  (6506007)  (52536014)  (2940 
100002)  (166002)  (450100002)  (9686003)  (81166007)  (83380400001)  (83080400001)  (1096003)  (550160 
02)  (33656002)  (21480400003)  (26005)  (186003)  (8676002)  (28085005)  (19627405001)  (8936002)  (5660 
300002)  (34756004)  (45080400002 ); DIR: INB; SFP : ; 


X-MS-Off ice3 65-Filter ing-Correlation-Id-Prvs :  cdeba52e-b82 6-4 6cf-8f 93-08d81cf 8f284 
X-Microsof t-AntispamAUatrustedr  BC'fi :  0; 

X-Micrcsoft-Ant.i.spam-Mes  sage-inf  o-Original  :  =  ?us- 

ascii?Q?f 8pQe3bus+Md2NpdVzA5BUq+jhikwQqS+MBQK/hNSi6uqT/ yBL+zy3W+LUSK?= 
=?US-ascii?Q?6RQ7T j j  53u0i'fcrkTahJMu42QQtne3BpkBw6 jR3kgLoV2kx/4RVeeM/PQnMs Jf= 
=?us-ascii?Q?zPJVWYEiOYqPca20yNq7heGvYyR8KQ/Z3jwU+S5XpibnriQn4ohhuN0sNJ7h?= 

=?us -ascii ?Q?xqEQakeME8GxrEoOzwQb8rABzEWAayY4zu!Kl2lrcgStMMs4p8pafln07G88rx?= 

=  ?us-ascii?Q?CzOC9YIP j A6x3++muLDiGBM4qNLrm7GeptYXtbncRSw51P j  FmeHnqZG3Z89T?= 
=?us-ascii?Q?5qgo8DlkMS5bzveF9Zs3AGlQQzoKXUmFjucRYD/YXDr3HeOFJOmwv8AgreA+?= 
=?us-ascii?Q?zVtXMS  JlqMIlolqilitfFgj  wwOPHNmNvz55Ob71sY3gGtS3U91MtbqWa0wj  gbP?= 
=?us-ascii?Q?qqvLPSyLlHJQsZQyHTaRmPNjHpK3DOE75wmnGxf/hn4hgYcg4dKTFNpOtsOO?= 
=?us-ascii?Q?Ix86FZX+B7oecfN88faS  j  c/v4W+LiGkXbPq6ier6GysB5bK8YbpMiX60VnNP?= 
=?us-ascii?Q?NSUB4V66PrWQjXX5VdI7FmiMPS9gOUVaDQZkBOsCHOw2Yp7MCHboKZ3LEuq?= 
=7us-ascii?Q?DupypWl  JvcDkauaWYFgb2GhsxlIePm53Csxbb7 /ew8iSittP6pUYMJjQYSBhpGK?= 

-?us-ascd  i  ?Q?  1 1  f U9i KYJDMfydHB l  YXxK/Wucmx/V\:by6r.tX4  P4wIKu.l  f  KuwRDFl  Z  I  I  XKbwHb?  = 
=7us-ascii?Q?X92kb2cTaVaYXXMNw3gJRf jplOVM7CTWw/YqsOMFSx/leeu611UHwfdHV21N?= 
=?us-ascii?Q?f  9cGsT/Fskh¥r/kt  j:rnHwpCfe;2B4B7BXQmbc3wDl59Kfyx054  8wf  3avcB51iR?- 
=  ?us-ascii?Q?lmsOnVckpIF+ j  YzCn8TLj ioWGT/Bef 4  3Gtl/15OHnE5qWo3d+0ToIZf 7LeB8?= 
=?us-ascii?Q?bm/XMaQ3AdnNElxsd9fh4r5d42VC5WD8xJWsq9:zr«jaJjHOOtj:84CO92UEC0x?'= 

?us-asci.i  ?Q?sQdoG6oMquv5zQP/v9d'jDqwmxQi  cbGHUtYYrDinaNwVuyK/llSZgmaOTBcZx?-'- 
=?us-ascii?Q?lZx9WLT6AsDGDpfwZHJniW4Qqpf5CPwfYZAW3XqMy/SAwcdt6CT/RZmi+WwG?= 

=  ’?us-asci  i  ?Q?bKfm2e5yZjKcMeR2rvR57Vuo9b/wr:Ri,11  nl)m  ihtrXFZf  P5ZBOv'I’7M9b7xYT8? 
=?us-ascii?Q?pQI2U2WE5Xqz4WcZAlhYiHAbNHGKuvPgzolxeXPEyf 0YwY6RnIGsgWHot JJC?= 
=?ns-ascii?Q?hG5iBpZ/lAzaFuDB’M32K9KTyK;kq91t06VE6fcQ=3D=3Df?':i 
X-MS-Exchange-Transport-CrossTenantHeadersStamped:  MN2PR09MB5451 
X-Organi z at ionHeaders Preserved:  MN2PR09MB5451 . namprd09.prod.outlook.com 
X-CrossPremisesHeadersFiltered:  CCCASV02 .CCOUNTY.com 
X-CrossPremisesHeadersFilteredBySendConnector :  CCCASV02 . CCOUNTY . com 
X-OrganizationHeadersPreserved:  CCCASV02 .CCODNTY.com 

X-MS-Exchange-Transport-CrossTenantHeadersStripped:  CY1GCC01FT005 . eop- 
gccOl . prod .protect! ora . outlook . com 

x-Forefpont-Anfcispam-Repopt-UnfcPusfced:  CfB'5r162;;i::2l7 . 184 . 7  9;CTiff  :US;ljANG:en;;  SCL:,^ 

1 ; SRV : ; IPV: CAL; SFV: SKN; H : CCCASV02 . CCOUNTY . com; PTR: Inf oDomainNonexistent; CAT : NONE; SFTY : ; 
SFS :  (8936002)  (1096003)  (2940100002)  (86362001)  (186003)  (26005)  (34756004)  (28085005)  (1962740 
5001)  (6506007)  (5660300002)  (21480400003)  (83380400001)  (336012)  (8676002)  (450100002)  (450804 
00002)  (82310400002)  (109986005)  (52536014)  (55016002)  (33656002)  (9686003)  (81166007)  (356005) 
(7696005)  (83080400001)  (166002) ; DIRrINB; SFP : ; 

X-MS-Off ice3 65-Filter ing-Correlation-Id-Prvs :  ee2a547d-ab5b-4251-046a-08d81cfbl2d3 
X-Mierosof  t-Aniispam-Ctotrusted::  BCL :  0; 

X-Microsoft-Antispam-Message-Info-Original :  =?us- 

ascii  ?Q?  I  A8Vknoj  1  Bef sgBsvGGov6i270 J8M I  CYhTO'r./SzKqjb4  P4r./rmC8l)A6eVI,na? 

=?us-ascii?Q?kGRdf SV8AbNWgHKyxYP+GsEM+IBsYSC09eoRoPxS6PuAUQvay+cASaC5uTIQ?= 
=?us-ascii?Q?+ATkIyyzebwAXzaobqSguATGk8VJJmKlhUzDId5fOQUFExXqCOOORC9CxWJv?= 
=?US-ascii?Q?zuAFyDRBK4ZKY8YfpluNACedsV2YcZCR+TlJ+XYfMm9X0AoBxK8Qk23Esrli;|fe 
=  ?us-ascii?Q?201WYGKutz2bUozIX7RvfBXBh2kl03XXtFychomj  j  ZgGFgiwlhOi4kw7bm+g?= 

■  ?us-ascii?0?r.  PLJ'dHl  c.MeeKj  oOf  OCSQbr.hSSOSN'YOSWQbGra  jhdcK6/DQcbw6EXB01  pAvz.W? 
=?us-ascii?Q?56XfXAiLnOal3Bwe2cftl3GqozZiFtl/Gfie5qC85NrLlB2Eatnh6LbXlggO?= 
=?us-aseii?Q?D+qia07xe j  6x  I  WjyzrsMBdkcOSgtC4.MTUxqh8Bp5bXkGr.dCnDiLCz4  syExOE?” 
=?us-ascii?Q?klr22uOt2Va3awEy85BM4z0zoqvGS9743F4PA9amRUtr6ESmgkNpB4 Jg8J jiff— 

=  ?us-ascii?Q?xk/cgkRTVGXqj  fpi5 jpBBa8sM0havaTQI9810BeaNtda0FklWc97m9Vr/pWi?= 
=?us-ascii?Q?b4  6  JkxAIWGgjUTX50qqsYDcl3.H4ReCS6b8xpzan0hz+ZdCPPGzlkVj/jGzVN3?- 
=?us-ascii?Q? JC5BYMsUFWoTzdVPXHc3GwDfnPS9MRI++Rti3hKoMPWmiBeAHbHL0LtQilTb?= 
=?us-ascii?Q?50soDDesPhE'06  Jr2zdU4  6bgHgaZdbgk9w/Bj  ST28oGDTVls8ql00YSeP9+oB?= 
=?US-ascii?Q?3sIbIyqWyxTBboRakQGAxif r Cjqf /Alf 4FhBswcBK7 6R7ev//twQ+iT80E¥iiffe 
=?us-ascii?Q?W81+A4uzgeN3LS71+eVnFYV8epLH4bREL5tenmsIEsZm0qTRXVKNNKlt3mrq?= 
=?US-ascii?Q?zf/608MRskjpgghNSUXSiUSR5Wo+iEslblTq8H2vqxBdR06NvBDI3Mcws8IL?- 
=?us-ascii?Q?9NmkLzx4xhq0Xt/aMESxEaIbgwGwZBVPllt3wu0DWvB38nmNg9mslq4qHdJg?= 
=?us-ascii?Q?XtDidKGyjHUAaDyj8+6TQ+CFCtz3z:hvOD7Q155I/btcTTMUPmOq6v4AOrb8k?= 

=  ?us-ascii?Q? JKvFq+7  07GenPLm3XIx7Ddm8vUj  4fucvCxf T7  0Y3f 7bS9NNyWHZd3Mz5+F/ x?= 
=?us-ascii?Q?8GSZ0MNzE6M3ziYBjUw9z+VxqvS3xcK9C/N8UsC0zcoLQZEXX3ggXVRzBABF?= 
=?us-ascii?Q?5.0ttlf?2/h+7NSbeYAI9khOtQtYlybZM8oWC  jTUw— 30-3D?= 
X-MS-Exchange-Transport-CrossTenantHeadersStamped:  SN6PR09MB3151 
X-Crgani zationHeaders Preserved :  SN6PR09MB31 51 . namprd09 .prod. outlook . com 
X-CrossPremisesHeadersFiltered:  CCCASV02 . CCOUNTY . com 

X-Cross Premise s Headers Filtered BySendConnector :  CCCASV01 . CCOUNTY . com 
X-Orgar.izationHeacers Preserved :  CCCASV01  .CCOUNTY.com 


X-MS-Exchange-Transport-CrossTenantHeadersStripped:  CY1GCC01FT006 . eop- 
gccO 1 . prod . protection . outlook , com 
X-  For  e  f  ron  t  -  An  t  i  s  p  am-  Rep  opt 

CIP:162.217.184.79; CTRY : US; LANG : en; SCL : - 

1;  SRV,: ;  I PV : CAT, ; SFV: SKN; H : CCCASV01 . CCOUNTY .  com; PTK:  Inf oDomainNpnexi stent ; CAT: NONE; SFTY :  ; 
SFS :  (186003)  (166002)  (336012)  (19627405001)  (6506007)  (450100002)  (7696005)  (83380400001)  (260 
05)  (9686003)  (82310400002)  (83080400001)  (81166007)  (86362001)  (28085005)  (34756004)  (52536014 
)  (8936002)  (45080400002)  (5660300002)  (109986005)  (2940100002)  (21480400003)  (55016002)  (33656 
002)  (8676002)  (1096003 ); DIR: INB; SFP : ; 

X-MS-Of  f  ice365-FilteriBg-Correlation,-dEd-:Prvs : 

01e94b24-f074-4a45-lf3d-08d81cfd31bf 
X-Mierosof  t-Antispamj:  S® :  0  ; 

X-Microsoft-Antispam-Mes sage-info : 

=  ?us-ascii?Q?at7gbnaTSLH8A5cbAl/S«Tr4t9MfWOWoGXtAgigIMxAj  7L4hR/yKXJrliB6A4  ?= 
=?US-ascii?Q?g0Mv5clGYix4qt3LdEm2nAVAgs6blT2YXHmJIFpjtvO7pKSJZV+8f JuFflE)£f= 
=?us-ascii?Q?KwMi+aYTTlTVZgKNSl+cmFhIYAXUlljq+3wBZu+16CfWXzaYX2RHF9humurj?= 
=?us-ascii?Q?N8ipQh.cnOs4ES/jMzCvELptRld6ECQHKNJqCNjuWQSegrt7mMH9PWbrOaAoC?- 
=?us-ascii?Q?5sds6MmjVI3k/FnEqWwW4gq5R8KYGGvWITREWuW5myG6jcT7VklL56d7Ep4w?= 
=?us-ascii?Q?wSqLzAJ6HXRrA9CtstrfMHuABuwDFLlNFY/TcQc5AMPydmbumrCPsEa6Yq30;f= 
=?us-ascii?Q?AOakeSZMFylzEFWf jUxdJnxbo4YG07TGeqNDJLgzlECZcJURWJNU8+hlkdPQ,?= 
=?us-ascii?Q?zX+GItRjmlhDfQeZJJfMa3QGJPL/ace2afGbFMgc9+4iIxn7fHUIS59StZ9G?= 
=?US-ascii?Q?vST/r»Bu9cZ4LDekBF12XPl5OzBvO22i0aZn85HGse92mhMA12YcngxZe/W6f- 
=  ?us-ascii?Q?lloVvkjqJPS7djpC/zF5g8f j  SAyVt+lMpcyLoaUrn+Qpt+7AWS33sMB7KRut?= 
=?us-ascii?Q?VXrFJFxGlBLSdpLo87dafpExFu7  6in2+SyQuH:@l;o/w4NHbembJqWy/fKwwiG?= 
=?us-ascii?Q?i JnN+Pwf 3ke4fOPabeuHvlnDHDcP5iZAVHf FCNE3EM03f oqcnNtYFWQpY8xH?= 
=?us-ascii?Q?pOxAIvtR40JlZfHGEx7FDONOicxM5NJCGCqCOibRFzT/zXynYTydROuMa05G?= 
=?US-ascii?Q?UjdSF2EB2+E’WpHlc»iSnyqeWfC8YfAU61YL8dfIMiWzKyfdQ8cAlD9a8ArlP?= 
=?us-ascii?Q?p7Rgr6O8tzN/5jcauhxzA2bvDmDp43G07ZxIIzYZMTAJfX9erPwQe/5XSPXg?= 
=?us-ascii?Q?5SHpbJq2Yl!ji:rGOoprU/WFOaf  reMVfbTscKIeCmwvyaoPzPd0vyZDSMhorI7P?= 

=  ?us-ascii?Q?L0zBJf DhAMp4P4kQnIpAA6HAUssMzrDj  KI0z7PFWSsidmotK7QM5KZ5X0S/H?= 
=?us-ascii?Q?fklIiStfZz5av3twkxxRAhFQzKlXBsnWvBZkpS/ jWoPOtSL5bC[ftiW/lt3vNM5E?‘=! 
=?Us-ascii?Q?OpFsqDfells?/2hsTM?DX4WQXVWfXAXlVMsr3e91nyfMyu25uLfKAt3UjWeHQl?- 
=?us-ascii?Q?pASWdVh4EEsl0XdZnbh2PZqF6yz6quRcDlQc+cH5PPneE9OUYkAQOdtlfV/0?= 
=?US-asCii?Q?eUxpX71twPw0i!icq3ivc2oo7FiYVSuqNLiscUA=3D=3Df=i= 

X-OriginatorOrg:  cookcountyil . gov 

X-MS-Exchange-CrossTer.ant-Origir.al Arrival Ti me :  30  Jun  2020  13:55:32.4088 
(UTC) 

X-MS-Exchange-CrossTenant-Network-Message-Id:  e59b4440-f289-4c42-0024-08d81cfd418d 
X-MS-Exchange-CrossTenant-Id:  8b4d55ae-6db4-4e05-a85c-59d6a256cd6e 

X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectinglp :  Tenantld=8b4d55ae-6db4- 
4e05-a85c-59d6a256cd6e;'Jp=tl62.-2l7.184.79]  ;  Helo-  [CCCASV01  .  CCOUNTY  .  com] 
X-MS-Exchange-CrossTenant-AuthSource : 

CY1GCC01FT006 . eop-gccOl .prod. protection . outlook.com 
X -MS - K. x ch an ge -C r o s sTer. a r. t - Au th As :  Anonymous 
X-MS-Exchange-CrossTenant-FromEntityHeader :  HybridOnPrem 
X-MS-Exchange-Transport-CrossTenantHeaders Stamped:  DM6PR09MB5221 
X-Organi z at ionHeaders Preserved:  DM6PR09MB5221 . namprd09.prod.outlook.com 
X-CrossPremisesHeadersFilteredByDsnGenerator : 

DM6PR0  9MB5221 . namprdO  9 .prod , outlook . com 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

From:  CCSO  Intel  (Sheriff)  <CCSO.INTEL@cookcountyil.gov> 

Sent:  June  30,  2020  8:07:45  AM  CDT 

Received:  June  30,  2020  8:55:33  AM  CDT 

Attachments:  (U--FOUO)  MB  -  Criminal  Hackers  Target  US  Law  Enforcement  Data 

06262020.pdf 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated  June  29, 
2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a  hack-and-leak 
operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support  of  or  in  response  to 
nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years  of  data  from  200  police 
departments,  fusion  centers,  and  other  law  enforcement  training  and  support  resources  around  the  globe,  according 
to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack-and-leak  activity  against  the  Russian 
Government. 

If  you  no  longer  wish  to  be  on  this  distribution  list,  please  send  an  email  to  ccso.intel@cookcountyil.gov  to  discontinue  receiving 
these  emails.  If  you  would  like  any  member  under  your  command  to  receive  these  emails,  please  send  an  email  to 
ccso.intel@cookcormtyil.gov  and  include  their  name,  title  and  email  address  in  the  body  of  the  request. 


Cook  County  Sheriffs  Office 
Strategic  Operations  Center 
3026  S.  California  Avenue 
Building  5,  2nd  Floor 
Chicago,  IL.  60608 
Office:  773-674-2694  or  8477 
Fax:  773-674-4797 


THIS  IS  A  CONFIDENTIAL  LAW  ENFORCEMENT  COMMUNICATION.  The  contents  of  this  e-mail  message  and  any 
attachments  are  intended  solely  for  the  addressee(s)  named  in  this  message.  This  communication  is  intended  to  be  and  to  remain 
confidential.  If  you  are  not  the  intended  recipient  of  this  message,  or  if  this  message  has  been  addressed  to  you  in  error,  please 
immediately  alert  the  sender  by  reply  e-mail  and  then  delete  this  message  and  its  attachments.  Do  not  deliver,  distribute,  transmit 
or  copy  this  message  and/or  any  attachments  and  if  you  are  not  the  intended  recipient,  do  not  disclose  the  contents  or  take  any 
action  relative  to  the  information  contained  in  this  communication  and/or  attachments.  This  e-mail  and  any  attached  documents 
may  contain  For  Official  Use  Only  and/or  Law  Enforcement  Sensitive  material  and  should  not  be  disseminated  outside  of  official 
law  enforcement  channels.  The  information  contained  in  this  message  as  well  as  any  attachments  shall  not  be  released  to  the 
media  or  the  general  public. 


Undeliverable:  Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law 
Enforcement  Data 


From:  Microsoft  Outlook 

<MicrosoftExchange329e71ec88ae4615bbc36ab6ce41 109e@cookcountyil.gov> 
To:  CCSO.INTEL@cookcountyil.gov,  Alexander.Brodie@cookcountyil.gov, 

Lisa.Farinella@cookcountyil.gov,  Kevin.Graff@cookcountyil.gov, 
Kevin.Cooper@cookcountyil.gov,  Kevin.Christofidis@cookcountyil.gov, 
Kelly.Sweeney@cookcountyil.gov,  Jonathan.Mobley@cookcountyil.gov, 
John.Steed@cookcountyil.gov,  John.Pradun@cookcountyil.gov, 
Jeffrey.Pasqua@cookcountyil.gov,  James.Scannell@cookcountyil.gov, 
James.Hughes@cookcountyil.gov,  Lissette.Rivera@cookcountyil.gov, 
Giovanni.Veitkus@cookcountyil.gov,  Gary.Newsom@cookcountyil.gov, 
Frank.Caridei@cookcountyil.gov,  Felix.Arvelo@cookcountyil.gov, 
Diane.Haras@cookcountyil.gov,  David. Delgadol @cookcountyil.gov, 
Daniel.Strong@cookcountyil.gov,  Daniel.Burke@cookcountyil.gov, 
Cedric.Mccloud@cookcountyil.gov,  Catherine.Domine@cookcountyil.gov, 
Anthony.Burns@cookcountyil.gov,  Gary.Rizzo@cookcountyil.gov, 
Luis.Santoyo@cookcountyil.gov 
Sent:  June  30,  2020  8:55:43  AM  CDT 

Received:  June  30,  2020  8:55:46  AM  CDT 

Attachments:  Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

Delivery  has  failed  to  these  recipients  or  groups: 

Alexander.Brodie@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Lisa.Farinella@cookcountyil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Kevin.Graff@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Kevin.Cooper@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Kevin.Christofidis@cookcountyil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Kellv.Sweenev@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Jonathan.Moblev@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 


configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


John.Steed@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


John.Pradun@cookcountyil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Jeffrev.Pasgua@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


James.Scannell@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


James.Hughes@cookcountyil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Lissette.Rivera@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Giovanni.Veitkus@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Gary.Newsom@cookcountyil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Frank.Caridei@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Felix.Arvelo@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Diane.Haras@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


David.Delqadol@cookcounWil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Daniel.Stronq@cookcounWil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Daniel.Burke@cookcounWil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Cedric.Mccloud@cookcounWil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Catherine.Domine@cookcounWil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Anthony.  Bu  rns@cookcounWil  .gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Garv.Rizzo@cookcounWil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Luis.Santovo@cookcounWil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


The  following  organization  rejected  your  message:  CYlGCC01FT007.mail.protection.outlook.com. 


Diagnostic  information  for  administrators: 

Generating  server:  CCCASV02.CCOUNTY.com 

Alexander.Brodie@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Flop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 


Usa.Farinella@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Flop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

Kevi  n .  G  raff  @cookcou  nty  i  I .  gov 
CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Flop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

Kevi  n .  Cooper@cookcou  nty  i  I .  gov 
CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Flop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

Kevin.Christofidis@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Flop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

Kelly.Sweeney@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Flop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

Jonathan.Mobley@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Flop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gccO  1 .  prod .  protection  .outlook.com]' 

John.Steed@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Flop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

John.Pradun@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Flop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

Jeffrey.Pasqua@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Flop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gccO  1 .  prod .  protection  .outlook.com]' 

James.Scannell@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Flop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

James.Hughes@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gccO  1 .  prod .  protection  .outlook.com]' 

Lissette .  Rivera  @cookcou  nty  i  I .  gov 
CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gccO  1 .  prod .  protection  .outlook.com]' 

Giovanni.Veitkus@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 


Gary-Newsom@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

Frank.Caridei@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

Felix.Arvelo@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

Diane.Haras@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

David.Delgadol@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gccO  1 .  prod .  protection  .outlook.com]' 

Daniel.Strong@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gccO  1 .  prod .  protection  .outlook.com]' 

Daniel.Burke@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

Cedric.Mccloud@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

Catheri  ne.  Domi  ne@cookcountyi  I  .gov 
CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gccO  1 .  prod .  protection  .outlook.com]' 

Anthony.Burns@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

Ga  ry .  Rizzo@cookcou  ntyi  I  .gov 
CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gccO  1 .  prod .  protection  .outlook.com]' 

Luis.Santoyo@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gccO  1 .  prod .  protection  .outlook.com]' 

Original  message  headers: 

Received:  from  CCCASVQ2 , CCOUNTY.com  (10.124.40.40)  byCCCASV02.CCQUNTY.com 
(10.124.40.40)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 

ciphersTlS_ECBiffi_RSA_WITM _AES_128_GCM_SBA256)  id  15.1.1261.35;  Tue,  30  Jun 
2020  08:40:41  -0500 


Received:  from  GCC02-BL0-obe.outbound.protection.outlook.com  (10.124.186.250) 
by  CCCASV02 .CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(version=TLSl_2‘,  cipher-ThS_ECBBEJRSA_WITiB_AES_128_GCM_SHA256)  id 
15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:40:41  -0500 
Received:  from  DM6RR09CA0009.namprd09.prod.outlook.com  (2603:10b 6:5:160.:-: 22) 
by  DM6PR09MB4936.namprd09.prod.outlook.com  (2603 : 10b6 : 5 : 267 : : 11)  with 
Microsoft  SMTP  Server  (version-- -TLS  1_2. , 

C iphe r =TLS_ECDHE_RS A_W I TH_AE S_2 5 6_GCM_S HA3 8 4 )  id  15.20.3131.21;  Tue,  30  Jun 
2020  13:40:38  +0000 

Received:  from  CYlGCC0lFT010.eop-gcc01.prod.protectioh.0utlook.com 
(2a01:lll:f400:7d02::209)  by  DM6PR09CA0009 . outlook. of fice3 65 . com 
(2603 : 10b6:  5  : 160  :  :22)  with  Microsoft  SMTP  Server  (versi@n?*ThSl_2, 
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3153.20  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:40:38  +0000 
Authentication-Results:  spf=softfail  (sender  1?  is  162.217.184.79) 
smtp ,mailfrom=cookcountyil . gov;  cookcountyil.gov;  dkim=none  (message  not 
signed)  header .  d' -none ;  cookcounty.il  .  gov;  dmarc=fail  actionnhone 
header . f rom=cookcountyil . gov; 

Received-SPF:  SoftFail  (protection.Qutlook.com:  domain  of  transitioning 
cookeountyil.gov  discourages  use  of  1 62. 217. 184. 79  as  permitted  sender) 
Received:  from  CCCASV01.CCOUNTY.com  (162.217.184.79)  by 
CY1GCC01 FT01 0 .mail .protection . outlook . com  (10.97.0.149)  with  Microsoft  SMTP 
Server  (version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 
15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:40:38  +0000 
Received:  from  CCCASV02.CCOUNTY.com  (10.124.40.40)  by  CCCASV01.CCOUNTY.com 

(10.124.40.39)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher^TlS_ECDBE_RSA_WITl_AES_128_GCM_SHA256)  id  15.1.1261.35;  Tue,  30  Jun 
2020  08:40:06  -0500 

Received:  from  GCC02-BL0-obe.outbound.protection.outlpok.com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(version-TLSl_2 ,  cipher=TlS_ECDHE_RSA_Wl:T$_AES_128_GCM_SHA256)  id 
1  5.1  .1-2  61.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:40:06  -0500 
Received:  from  MWHPR09CA0026.namprd09.prod.outlook.com  (2 603 : 10b6 : 300 : 6d : : 12 ) 
by  DM6PR09MB4838.namprd09.prOd.outlook.com  (2603 : 10b6 : 5 : 265 : : 20 )  with 
Microsoft  SMTP  Server  (version=TLSl_2 , 

c  iph  e  .r-TT,  S_ECDHK_R  S  A_W  I  TH_AHS_256_GCM_SHA384  )  id  15.20.3131  .20;  Tue,  30  Jun 
2020  13:40:04  +0000 

Received:  from  DM2GCC01FT005 . eop-gccOl .prod. protection . outlook.com 
(2a01:lll:f400:7d01::209)  by  MWHPR09CA0026 . outlook .office 3 65. com 
(2603 : 10b6 : 300 : 6d: : 12 )  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
ciphejr-Tt,S_ECDHE_RSA_WITH_AES_256_GCM_SHA384)  id  15.20.31  53.20  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:40:03  +0000 
Authentication-Results-Original :  spf=softfail  (sender  IP  is  162.217.184.79) 
smtp. mailf roai=3,t1dekcountyii. gov;  eookcouhtyil.gov;  dkim--npne  (message  not 
signed)  header . d=none; cookcountyil . gov;  dmarc=fail  action=none 
header .  from- --cookcountyil .  gov; 

Received-SPF:  SoftFail  (protection.outlook.com:  domain  of  transitioning 
cookcountyil .gov  discourages  use  of  1 62. 217. 184. 79  as  permitted  sender) 
Received:  from  CCCASV02.CCOUNTY.com  (162.217.184.79)  by 
DM2GCC01FT005.mail.protection.outlook.com  (10.97.3.0)  with  Microsoft  SMTP 
Server  (vers ioft^T.h§  1  _2 ,  cipher-TLS_^DE3R_RSA_WlTH_AES_128_GCM_SHA256)  id 
15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:40:03  +0000 
Received:  fromCCCASV02.CCOUNTY.com  (10.124.40.40)  byCCCASV02.CCOUNTY.com 

(10.124.40.40)  with  Microsoft  SMTP  Server  (versidn=TLSl  2, 

cipher=TLS_ECDHE_RSA_WITH_AES_12 8_GCM_SHA2 5 6 )  id  15.1.1261.35;  Tue,  30  Jun 
2020  08:24:59  -0500 

Received:  from  GCC02-DM3-obe.outbound.protection.outlook.com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 
15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:24:59  -0500 
Received:  from  BN6PR09CA0066.namprd09.prod.outlook.com  (2603 : 10b6 : 404 : 7a : : 28) 
by  DM6PR09MB4591.namprd09.prod.outlook.com  (2603 : 10b6 : 5 : lb9 : : 10)  with 
Microsoft  SMTP  Server  (version=T:LSi^_2, 

cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3131.21;  Tue,  30  Jun 
2020  13:24:57  +0000 

Received:  from  DM2.GCC01  FT008 .  epp—gccOl  .prod,  protection  -  outlook,  com 
(2a01:lll:f400:7d01: :209)  by  BN6PR09CA0066.outlook.office365.com 


(2603 : 10b6 : 404 : 7a : : 28)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher— TTS_ECESHE_RSA_WITH_AES_2 5 6_GCM_SHA3 8 4 )  id  15.20.3153.20  via  Frofrfcend 
Transport;  Tue,  30  dim  2020  13:24:57  +0000 
Authentication-Results-Original :  spf=softfail  (sender  IP  is  162.217.184.79) 
smtp.mai  1  f rom-cockcountyil  .cov;  cookcounty.il  .gov;  dkim—npne  (message  not 
signed)  header . d=none; cookcountyil . gov;  dmarc=fail  action=none 
header . f rom—ccokcountyil . gov; 

Received-SPF:  SoftFail  (protection.outlook.com:  domain  of  transitioning 
Cookcountyil.gov  discourages  use  of  162.217.184.79  as  permitted  sender) 
Received:  fromCCCASV02.CC0USTY.com  (162.217.184.79)  by 
DM2GCC01FT008.mail.protection.outlook.com  (10.97.3.193)  with  Microsoft  SMTP 
Server  (vers  iohVftS  1  _2 ,  ciphep-TLS  ^&DSE_RSA_WITH_AES_128_GCM_SHA256)  id 
15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:24:56  +0000 
Received:  fromCCCASV02.CCOUSTY.com  (10.124.40.40)  byCCCASV02.CCOUSTY.com 
(10.124.40.40)  with  Microsoft  SMTP  Server  (versi.On=TLSl  2, 

cipher=TLS_ECDHE_RSA_WITH_AES_12 8_GCM_SHA2 5 6 )  id  15.1.1261.35;  Tue,  30  Jun 
2020  08:09:46  -0500 

Received:  from  GCC02-BL0-obe.outbound.protection.outlook.com  (10.124.186.250) 
by  CCCASV02 . CCOUNTY . com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(version  TT,S1_2 ,  cipher=TLS_EC0flE_RSA_WITi_AES_12 8_GCM_SHA2 56)  id 
15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:09:46  -0500 
Received:  from  CY4PR09CA0087.namprd09.prod.outlook.com  (2603:10b6: 903:c7: :25) 
by  BY5PR09MB5777.namprd09.prod.outlook.com  (2603 : 10b6 : a03 : 246 : : 8)  with 
Microsoft  SMTP  Server  (version=TLSi_2 , 

cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3131.21;  Tue,  30  Jun 
2020  13:09:41  +0000 

Received:  from  DM2GCC01FT007 . eop-gccOI .prod. protection, outlook. com 
(2a01:lll:f400:7d01: :208)  by  CY4PR09CA0087.outlook.office365.com 
(2603 : 10b6 : 903 : c7 : : 25 )  with  Microsoft  SMTP  Server  (version-TLSl_2, 
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3131.21  via  Frontend 
Transport;  Tue,  30  Jun  .2020  13:09:41  +0000 
Au  then  t  .i.  cat  ion  -Re  su  1 1  s  -0  r  i  gi  nal  :  spf  softfail  (sender  IP  is  1  62 .217 .184.79) 
smtp ,mailfrom=cookcountyil . gov;  cookcountyil.gov;  dkim=none  (message  not 
signed)  'header. d=none; coakcotintyil.gov;  dmarc=fail  aetion^ftbne 
header . f rom=cookcountyil . gov; 

Received-SPF:  SoftFail  (protection, outlook. com:  domain  of  transitioning 
cookc0untyil.gov  discourages  use  of  1 62 .21 7 . 1 84 . 79  as  permitted  sender) 
Received:  from  CCCASV01.CCOUNTY.com  (162.217.184.79)  by 
DM2GCC01FT007  .maii,»protection. outlook. com  (10.97.3.159)  with  Microsoft  SMTP 
Server  (version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 
15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:09:40  +0000 
Received:  from  CCCASV02.CCOUNTY.com  (10.124.40.40)  by  CCCASV01.CCOUNTY.com 
(10.124.40.39)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher=TLSMECD3ft_RSA_WITt_AES_128_GCM_SHA256)  id  15.1,1261.35;  Tue,  30  Jun 
2020  08:08:34  -0500 

Received:  from  GCC02-BLO-obe.outbound.protection.oUtlOok.com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(ver:s.icn-TLSl_2 ,  ci  phen  T'[,S_:-;CDfiE_RSA_W  l'TH_AKS_l  2  8_GCM_SKA2 56)  id 
15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:08:34  -0500 
Received:  from  BL2PR09CA0033.namprd09.prod.outlook.com 
(2a01: 111 : e400 : c743 : : 4 3 )  by  MN2PR09MB57  85.namprd09.prod.oUtlook.com 
(2603 : 10b6: 208 : 21f : : 20)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher=¥LS_E#0Iffi__RSA_WITl_AES_256_GCM_SHA384)  id  15.20.3153.20;  Tue,  30  Jun 
2020  13:08:30  +0000 

Received:  from  DM2GCC01FT005 . eop-gccOI .prod. protection . outlook.com 
(2a01 : 111 : f 400 : 7d01: :205)  by  BL2PR09CA0033 . outlook. of fice365 . com 
(2a01 : 111 : e400 : c743 : : 43)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher=¥lS_ECDRE_RSA_WITH_!kES_256_GCM_SHA384);  id,  15.20 . 3131.21  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:08:30  +0000 
Authentication-Results-Original :  spf=softfail  (sender  IP  is  162.217.184.79) 
smtp .mailfrom— cookcountyil. gov;  cookcoUhtyil.gov;  dkim*=jaone  (message  not 
signed)  header . d=none; cookcountyil . gov;  dmarc=fail  action=none 
header . f rcm-eookcountyil . gov; 

Received-SPF:  SoftFail  (protection.outlook.com:  domain  of  transitioning 
cookcountyil.gov  discourages  use  of  162  ..217 . 184 . 79  as  permitted  sender) 
Received:  fromCCCASV01.CC0USTY.com  (162.217.184.79)  by 
DM2GCC01FT005.mail.protection.outlook.com  (10.97.3.0)  with  Microsoft  SMTP 


Server  (version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 

15.20.3131.20  via  Frontend  Transport/  fue,  30  Jim  2020  13:08:30  +0000 
Received:  from  CCCASV02.CCOGNTY.com  (10.124 .40.40)  byCCCASV01.CCOUNTY.com 

(10.124.40.39)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 

cipher =TL'S  E0DSIL'  RSA_WITH_AES_12 8_GCM_SHA2 56)  id  15.1.1261. 35 ;  The ,  30  Jun 

2020  08:08:21  -0500 

Received:  from  GCC02-BI,0-obe .  outbound  .protect: ion  .outlook .  com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 
15.1.1261 .35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:08:21  -0500 
Received:  from  BL0PR0901CA0030.namprd09.prod.outlook.com 
(2603:1 0b6:208:lc0::40)  by  SA9PR09MB5230 . namprdO 9 .proa. outlook . com 
(2603 : 10b6: 806 : 45 : : 10)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher=TLS^ECDiliE__RSA_WITS_jAES_2 5 6_GCM_SHA3 8 4 )  id  15 . 20 . 3131 . 23;  Sue,  30  Jun 
2020  13:08:19  +0000 

Received:  from  DM2GCC01FT006 . eop-gccOl .prod. protection . outlook.com 
(2a01: 111 : f 400 : 7d01: :203)  by  BL0PR0901CA0030 . outlook . of fice365 . com 
(2603 : 10b6 : 208 : IcO : : 40)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher=T£s_ECt®E_RSA_WITH_AES_256_GCM_SHA384)  id  15.20.3153.20  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:08:19  +0000 
Authentication-Results-Original :  spf=softfail  (sender  IP  is  162.217.184.79) 
smtp .mailf rom^C'OOkcountyi,!.. gov;  cookcountyil.gov;  dkim^pone  (message  not 
signed)  header . d=none; cookcountyil . gov;  dmarc=fail  action=none 
header .  f  rcm--eookccuntyil .  gov; 

Received-SPF:  SoftFail  (protection.outlook.com:  domain  of  transitioning 
cookcountyil.gov  discourages  use  of  162.217.184.79  as  permitted  sender) 
Received:  fromCCCASV01.CCOUNTY.com  (162.217.184.79)  by 
DM2GCC01FT006.mail.protection.outlook.com  (10.97.3.107)  with  Microsoft  SMTP 
Server  (versioit=TLSl_2 ,  cipher=TLS  ECOR£jlSA_WITH_AES_128_GCM_SHA256)  id 

15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:08:19  +0000 
Received:  fromCCCASV02.CC0UNTY.com  (10.124.40.40)  byCCCASV01.CCOUNTY.com 

(10.124.40.39)  with  Microsoft  SMTP  Server  (version-Tl<Sl_2/ 

cipher=TLS_ECDHE_RSA_WITH_AES_12 8_GCM_SHA2 5 6 )  id  15.1.1261.35;  Tue,  30  Jun 
2020  08:08:15  -0500 

Received:  from  GCC02-DM3-obe.outbound.protection.outlook.com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(version=TLSl_2u  ciphep— ffiUS_ECDRE_RSA_Wi'fi_AES_128_GCM_SHA256)  id 
15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:08:15  -0500 
Received:  from  BN3PR09CA0064.namprd09.prod.outlook.com  (2603 : 10b6 : 400 : 3 : : 32) 
by  SA9PR09MB5168.namprd09.prod.outlook.com  (2 603 : 10b6 : 806 : 41 : : 12 )  with 
Microsoft  SMTP  Server  (version~TLSl_2 , 

cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3131.20;  Tue,  30  Jun 
2020  13:08:11  +0000 

Received:  from  DM2GCC01 FT009 . eop-gccOl .prod. protection .outlook . com 
(2a01:lll:f400:7d01: :207)  by  BN3PR09CA0064.outlook.office365.com 
(2603 : 10b6 : 400 : 3 : : 32)  with  Microsoft  SMTP  Server  (versiahv'J?RSl_2, 
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3131.20  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:08:10  +0000 
AUthenticatioh-ResUlts-Original :  spf  softfai.l  (sender  IP  is  162.217.184.79) 
smtp ,mailfrom=cookcountyil . gov;  cookcountyil.gov;  dkim=none  (message  not 
signed)  header .  d=none ;  cookcountyil .  gov;  dmarc=f ail  actiW^fSQne 
header . f rom=cookcountyil . gov; 

Received-SPF:  SoftFail  (protection, outlook. com:  domain  of  transitioning 
cookeouhtyll.gov  discourages  use  of  162.217.184.79  as  permitted  sender) 
Received:  from  CCCASV02.CCOUNTY.com  (162.217.184.79)  by 
DM2GCC01FT009 .mail, protection, outlook. com  (10.97.2.68)  with  Microsoft  SMTP 
Server  (version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 

15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:08:10  +0000 
Received:  from  CCCASV02.CCOUNTY.com  (10.124.40.40)  by  CCCASV02.CCOUNTY.com 

(10.124.40.40)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 

cipKer-Ti,S_ECBEE  RSA_WITH  AES_128_GCM_SHA256)  id  15.1.1261.35;  Tue,  30  Jun 
2020  08:07:54  -0500 

Received:  from  GCC02-BL0-obe . outbound .protection . outlook . com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(version  TLS1_2,  ciphep=ThU_ECDaE_RSA_WlTii_AES_128_GCM_SHA256)  id 
1 5 .  1,1201  .35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:07:54  -0500 
Received:  from  BL0PR0901CA0023.namprd09.prod.outlook.com 


(2603:1 0b6:208:lc0::33)  by  DM6PR09MB3225 . namprd09.prod.outlook.com 
(2603 : 10b6 : 5 : 35 : : 33 )  with  Microsoft  SMTP  Server  (vers i on1  -TLSl_2 , 
ciphet-TLS^EDDHE  RSA_WITH_AES_256_GCM_SHA384)  id  15.20.3131  .21;  Tue,  30  J'un 
2020  13:07:51  +0000 

Received:  from  DM2GCC01FT006 . eop-gccOl .prod. protection, outlook. com 
(2a01:lll:f400:7d01: :205)  by  BL0PR0901CA0023.outlook.office365.com 
(2603 : 10b6: 208  :  IcO  : :  33)  with  Microsoft  SMTP  Server  (version-TIiSl_2, 
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3131.21  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:07:51  +0000 
Authentication-Results-Original :  spf=softfail  (sender  IP  is  162.217.184.79) 
smtp .mailfrom=cookcountyil . gov;  cookcountyil.gov;  dkim=none  (message  not 
signed)  header: .  d'  :ncne ;  cookcountyil  .  gov;  dmarc=fail  actioifefisne 
header . f rom=cookcountyil . gov; 

Received-SPF:  SoftFail  (protection, outlook. com:  domain  of  transitioning 
CQOkeouhtyil.gov  discourages  use  of  1 62 .217 . 1 84 . 79  as  permitted  sender) 

Received:  from  CCCASV01.CCOUNTY.com  (162.217.184.79)  by 
DM2GCC01FT006 .maiiyprotection. outlook. com  (10.97.3.107)  with.  Microsoft  SMTP 
Server  (version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 
15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun_2020  13:07:51  +0000 
Received:  from  CCCASV02.CCOUNTY.com  (10.124.40.40)  byCCCASV01.CCOUNTY.com 
(10.124.40.39)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
ciphe£-TLS_EC0KE_RSA_WITH  AES_128_GCM_SHA256).  id  15,1.1261.35;  Tue,  30  dun 
2020  08:07:26  -0500 

Received:  from  GCC02-BL0-obe.outbound.protection.QUtlook.com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 
15.1 .1261 .35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:07:26  -0500 
Received:  from  CH2PR09MB4491.namprd09.prod.outlook.com  (2603 : 10b6 : 610 : 36 : : 19) 
by  CH2PR09MB4395.namprd09.prod.outlook.com  (2603 : 10b6 : 610 : 6d: : 18)  with 
Microsoft  SMTP  Server  (version=TLSl_2 , 

ciphe»-TLS__EODHE^RSA_WITH_AES_256_GCM_SHA384)  id  15.20.3131  .21;  Tue,  30  Jun 
2020  13:07:22  1 0000 

Received:  from  CH2PR09MB4491.namprd09.prod.outlook.com 
(  [fe80 : :54b4 : 1 a30 : 1 51 b : 81  Of ] )  by  CH2PR0 9MB4 4 9 1 . namprdO 9 . prod . outlook . com 
(  [fe80: :54b4:la30:151b:810f%5] )  with  mapi  id  15.20.3131.027;  Tue,  30  Jun  2020 
1  3:07:22  I  0000 

From:  "CCS0  Intel  (Sheriff) "  <CCSO.INTEL@cookcountyil.gov> 

Subject:  Pass  Through  -  (U//F0U0)  Criminal  Hackers  Target  US  Law  Enforcement 
Data 

Thread-Topic:  Pass  Through  -  (U//F0U0)  Criminal  Hackers  Target  US  Law 
Enforcement  Data 

Thread-Index :  AdZOUZRVrVUDcf01TiiWh3YEOiFXiAAj  ZyaaAAAHqe8= 

Date:  Tue,  30  Jun  2020  13:07:20  +0000 
Message-ID: 

<CH2PR09MB4491104495F32B729B402EA7F56F0@CH2PR09MB4491.namprd09.prod.outlook.com> 
References:  <LYRIS-103909956-141184 6-2020 . 06 . 29-15 . 13 . 38— isp-les- 

north#lists . illinois . gov@lists . illinois ,gov>,<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH 
2  PRO 9MB4  4  91 . namprdO  9 . prod . outlook . com> 

Ift-Reply-To: 

<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com> 

Accept-Language :  en-US 

Content-Language:  en-US 

X-MS-Has-Attach :  yes 

X-MS-TNEF-Correlator : 

Authentication-Results-Original :  cookcountyil.gov;  dkim=none  (message  not 
signed)  header. d~hone; cookcountyil.gov;  dmarCr=hone  acficraNnoae 
header . f rom=cookcountyil . gov; 
x-originating-ip:  [162 .217 .184 .194] 
x-ms-publictraf f ictype :  Email 
X-MS-0ffice3 65-Filter ing-HT :  Tenant 

X-MS-Of f ice3 65-Filtefing-Correlatiofi— Idi  d60cf 752-ee33-4 157-3 9fc-08d81cfb2cb5 
x-ms-traf f ictypediagnostic: 

CH2PR0  9MB  4  395:  | DM 6 PRO 9MB 3 2.2 5 :  | SA9PR09MB5168 :  | SA9PR09M35230 :  | MN2PR09MB5785 :  | BY5PR09M3577 
7: | DM6PR09MB4591 : | DM6PR09MB4838 : | DM6PR09MB4936 : 
x-ms-oob-tlc-oobclassifiers : 

OEM: 9508 ; OLM: 9508;OLM: 9508;OLM: 9508;OLM: 9508;OLM: 9508;OLM: 9508;OLM: 9508;OLM: 9508; 
X-Microsof t-Antispam-Untrusted :  BCL : 0 ; 


X-Microsoft-Antispam-Mes sage- Inf o-Original : 

i  I  uzE6hVl  cr.RsGSI  QWcn6TsXKHhKrGB2ApYs8V\:S'r.xl,g2Up0u820HRf'nsFp  t  9C  j  1  QecvSzXCwXpal AW04qrntKsl 
2q6Qw2oMnjCqqmlvLhbB607gMDIp2f 7mBL3QYwDQr+r4wNnGRAC9xe3+5GPOy8gsOxnY!C/tzY345eFTIOdpxi8h. 
rvmE/ovgAyrKD2M+aVOHraAlD6YgO/dp+AIa6uQJHM92dDHc+v9Nmf f f ieN4nF9HU5Sho5QfaoyzaceI9B/Iqgk 
rVdjSXovu2pQFCekwI)l  0  jsQ53r.  1  ecmH 8b9QGuQ"r;KneL2ev j  WMOddwO 7.d2mol)dY /WDuTa KA  I  Wa  JWmC PWl  pOBTj  ZB 
1592rts6hC49p2A= 

X-  For  e  f  r  on  t  -  An  t  i  s  p  am-  Rep  o  r  t  -United  s  t  e  d :  0X9*255  .-255.255*255;  CTRY : ;  LANG :  en ;  SCL :  - 
1 ; SRV : ; IPV: NLI ; SFV: SKI ; H : CH2PR09MB44 91 . namprd09 . prod. outlook . com; PTR: ; CAT : NONE; SFTY SF 
S : ; DIR: INB;SFP: ; 

x-ms -exchange-anti spam-messagedata: 

BuYbw0RoSBfECmAFs5sfpqFR/eESsNr+Plx06kdsYiyNoXFEYgS3Jz6QYqBwqdalBgTm5iebIlsncXRB6v4+RaV 
C42PElOHwFJBOAzNHKMxkCZCwRxlmubguafevanh98UlGYiSoqtiVFIMyzzqWjVwq2ALgG6TEoWTOD6wL3DHlg+ 
twaRUDU5pX7Y3UuqHnj  SUkkWpE3g+KMrlKiWDb6hsqAZsExSu0dRsfelbY5iawMgVlP06KM54AE4iNVyJ6s+PhZ 
oFB021MJN0zbzrKRmG517  6nAVkDQZ6LAJ59qRaYnm4V2jeg+UrmezaEAlBSTXRnJE7c4PfWdftZR7vsnGJ121P:DSr 
wlqBu5V9fQ0asbFFrSOauG9RYEIceEB«ji2qfNX9W5sCwVf+Z2W+dW0tMy5YgF7ghw6XrerqzMMShABE14TwG3sg 
hMkbytZTnSmqwnqf 05E2cPgyZHNVzIQHTfXbIbLbhC/ uOVat8cAb+pOhONzcOhHtduUMJV/ CgNncT 
x-ms -exchange- transport-forked;  True 
Content-Type:  multipart/mixed; 

boundary- "_004_CH2 PRO 9MB4 4 91 1 04495F32B729B402EA7F56F0CH2PR0 9MB4491namp_" 

Ml  ME- Vers ion :  1 . 0 

X-MS-Exchange-Transport-CrossTenantHeadersStamped:  CH2PR09MB4395 
X-OrganizationHeaders Preserved;  C1I2PRQ9MB4  395  .  namprdO 9  .prod. outlook .  com 
To:  Undisclosed  recipients:; 

Retuf n-Path :  CCSO .  [KTEl.@cookcour.tyil . gov 
X-CrossPremisesHeadersFiltered:  CCCASV02 . CCOUNTY . com 
X-CrossPremisesHeadersFilteredBySendConnector :  CCCASV01 . CCOUNTY . com 
X-OrganizationSeadersPreserved:  CCCASV01 .CCOUNTY.com 
X-EOPAttributedMessage :  7 

X-MS -Exchange-Transport-Cross Tenant Headers Stripped:  DM2GCC01FT006 . eop- 
gccOl .prod. protect ion . outlook.com 

X-Foref ront-Artispam-Report-Unteasted:  CIP;162  .-217 . 184 . 7:9;:CT’R¥;US;liANG:en;;  SCB;- 
1;  S RV ; f  j BV : CAL ;  SFV:  SKN;  H :  CCCASV01 .  CCQUfTY .  com;  PTR: InfoDomainllonexistent;  CAT  :NONE;  SFTY :  ; 
SFS :  (34756004)  (28085005)  (45080400002)  (9686003)  (8676002)  (166002)  (8936002)  (1096003)  (55016 
002)  (81166007)  (7416002)  (83080400001)  (52536014)  (26005)  (7696005)  (19627405001)  (86362001)  (2. 
1480400003)  (356005)  (82310400002)  (2940100002)  (33656002)  (336012)  (450100002)  (109986005)  (56 
60300002)  (186003)  (83380400001)  (6506007) ; UIR: 1  KB; SFP : ; 

X-MS-Of f i ce365-Fi 1 tering-Correl ation-Id-Prvs :  032051 42-5935-4a88-f 6ba-08d81 cf 6871 3 
X-Microsof t-Antispam-Untrusted :  BCL : 0 ; 

X-Mi cro soft-Anti spam-Me s s age- In fo-Origi nal :  =?us- 

ascii?Q?qqz2axaPsPt6cRhwprV+ioE4yFXF9neuzlx680KXimBZbJL5qP5Myc39zA10?= 

=?Us-ascii?Q?zON93FB/g/7egToohlpauUar4xP8,fLzJc8ttBf«JvBojS2dKYkZGOAAhJ/VO?“ 

=?us-ascii?Q?19s6wqLFJ4LQMzyaU4uFCavEdnOoembTpISLdDi/DsZ3XWoCOP/CsmwBbapP?= 

=  ?us-ascii?Q?i3zuVExuALmj lCDltxkMREfYV3NoGgazwkweui2VjMTubkYGoHpiPsnfpFKj  ?= 
=?US-ascii?Q?BcWkcx7tg7  9KwlxWUmKAeADlDQ6dEAGEbOS7nMA2Yt+/hJURVhFFmOesqbNN'?= 
=?us-ascii?Q?mkHh8B6oSqixPVXWx7wk2CAFrZIIIVMqQLHdTLu3HK01IeosglyNQaniTmwA?= 
=?US-ascii?Q?WXs6y7ZSlEqNFeFlMT721cipk9/QpeIPxQgTsNpxzPUUyYADYoSwlmC+UQHW?= 
=?us-ascii?Q?rXj WLAebvMpJGwyWgj AlXceB+qx8bksgdSGOOCD5albP2IllelQeE/Aa8ThE?= 
=?us-aseii?Q?NvTxMZlil«JUnmoV+gwu/tt8iUbUEUz6aEP8nxggjU5hxRX+StdZqOSbti>r7WpHk?= 
=?us-ascii?Q?Bvapgf9n5Z6upE6BOkOo8ryPyTLCkeNNT3Jr05+ME7qeraotItplVtlXc5fD?= 
=?us-ascii?Q?aVHKxWYddelpoCRiIHRSGLGBQwzMORuHrmKSWgjb2QHXAyVuIeMzlT91 Jav?= 
=?us-ascii?Q?DQCycNLmNDRjb0FArmuR+RSCLQcSa7Y3flqMWS4Prb04kgJrD+8/ccgHayF0?- 
=  ?us-ascii?Q?v4PlKvLymI9199+BhrBJhvtfRpOvDUbm/BVRnuY7sykmE j  tAkS JPgtX12wQ4  ?= 
=?us-ascii?Q?7  7mznmNzDLm/i/aA4ZP+alxlnKf,e3DumwctuLmv3FvGFyf  tlCWWQbQ2R6tR3fs=: 
=?US-ascii?Q?gkkTo:uT6a40t3tDdfzdMIUfMauxg50MfFkFtYpygOT/YMtYXDvj QOhOP5Aib?= 
=?us-ascii?Q?100MtEs0GpGhyn71DXIQhztnMPSKblKy4ZuBXKloLqMyQJg/LgwJ9IvNGcRg?= 
=?US-ascii?Q?+ua3FbftZ‘tPTbQI/gHkoofEwyeTBQh0ttXwmU5gIwWhS61/AQdD+nkCMp53XS?= 

=  ?us-ascii?Q?pfwf rOMmqGLZ7  4i+MaO j vaYQkcp6sknCUKZibUOaA6gS4cdhLHcAhZONdtU2  ?= 
=?US-ascii?Q?/£uUVt/hcqdcf  lilqp3cNda7KyMrw,60GLPPI*AlyeZ+gqlmi80X2eiSnmGkEd?= 
=?us-ascii?Q?JgUSd+3E+iq7zXi8E+oic7eQ6I7H8/OrvrGoUbxToDFP0in/nSyl730Gk2Et?= 
=?us-ascii?Q?M001E8+QcBNaPYdP38wlYV/mMjVrdFNMacH8vA=3D=3D?= 
X-MS-Exchange-Trapspott-CrossTenantHeaders Stamped:  DM6PR09MB3225 
X-OrganizationHeaders Preserved:  DM6PR09MB3225 . namprd09.prod.outlook.com 
X-CrossPremisesHeadersFiltered:  CCCASV02 .CCOUNTY. com 
X-CrossPremisesHeadersFilteredBySendConnector :  CCCASV02 . CCOUNTY . com 
X-OrganizationHeacersPreserved :  CCCASV02 .CCOUNTY.com 

X-MS-Exchange-Transport-CrossTenantHeaders Stripped:  DM2GCC01PT009 . eop- 
gccOl .prod. protection . outlook.com 


X-Forefront-Antispam-Report-Untrusted:  CIP : 162 . 217 . 184 . 7 9; CTRY : US; LANG : en; SCL : - 
1;  SRV: ; IPV : CAL; SFV: SKN; H : CCCASV02 . CCCUNTY . com; BTRjInf oPomainNonexistent; CAT : NONE; SFTY : ; 
SFS :  (109986005)  (86362001)  (83380400001)  (166002)  (5660300002)  (21480400003)  (82310400002)  (81 
166007)  (2940100002)  (83080400001)  (28085005)  (34756004)  (26005)  (450100002)  (9686003)  (186003) 
(3.36012)  (55016002)  (7696005)  (19627405001)  (52536014)  (6506007)  (8676002)  (8936002)  (1096003)  ( 
7416002)  (45080400002)  (33656002 ); DIR: INB; SFP : ; 

X-MS -Off ice365-Fi lfceri.ftg~Corr  elation^  Xd.^B.rys :  0el33ael-4d70-4c57-3dfa-08d81cf 69835 
X-Microsof t-Antispam-Untrusted :  BCL : 0 ; 

X-Microsoft-Antispam-Message-Info-Original :  =  ?us- 

ascii?Q?eVb9CDSfm7BNFNbT91 j  GqNf AedtAy+gYwblBEQ8yhaqNd3alRQpq6gwtLiTL’?= 
=?us-ascii?Q?7Bilm9qpTeSie4GROzb6dV2eUvTKysrTe4ESZB5AEFQYs9ddXwbqz9G6/ThH?= 
=?us-ascii?Q?H89FT+AU6krnlDvEOpW4/JBJNjdVCwrouuTbeJTXBynVbza640ZAlYkawWK/?- 
=?us-ascii?Q?HrAnBYnGWAWF9jtDi7t3MHrkcMlytpFTLI14C17YoZk09iGB03Ptp4slLjse?= 
=?US-ascii?Q?BFbPbObAYwTgj  klQr+WtC4QhslSu82SEhMSb9mCKnrSWyDkj  4  7S.eyV4z8Zenj’5s 
■  -?us-ascd  i  ?Q?1  GcVm53v  I  6";Ml,m0C75uV/12KA6VK?,h07xeI.i.xpJwnaXgj  !Av7 srl  p66xl  yi  Tfv 
=?us-ascii?Q?yRxeCaG0RFT+61suYs5mlYUitXbrZuRYzbUneoHQeQbHFZmZGgZDlLuHrN9B?= 
=?US-ascii?Q?sso+dBmmmVBG81ElrOFzer9PB6BpQtP7+qUGSsWfPaiNjS7fi7Hf  cRS  JrxgmHn?— 
=?us-ascii?Q?eUxlpTp3hDsgCQrqwuXdu8slIFuxwJ72px7r5HOawGOQgGf i6t JfuugTyxBX?= 
=?US-ascii?Q?tKamJyXzJfrDQoRk63GHGPgTVGVih7u/+ybUQeLBGUdIGzoStlX®UgcWRQdi?= 
=?US-ascii?Q?66W9ktm4FOBws3cYNl£,h67nOOeolK5m9LOJKiTIIoWcfUQBv6K/J4Bywd4TQ.-?= 
=?us-ascii?Q?23A31b9uWY9X3dIa+/wFt0kqqArAHNLYY8YlRxw4bX/UNtKqbl8nfnVx9M7K?= 

'  ’?us-asci  i  ?Q?nxS2Qmm04aK2NMKJSB08s3kUFK3  lEQCZr'.fbAYIAVR4  jzDI,42cJPz7qI,TCeAC?--' 
=?us-ascii?Q?uh6KI/izKS4LvcUezEJt3mab0t3EIHVp2SFYQVndbPRWaGtAuP+yp7knXsGX?= 
=?us-ascii?Q?AATNK8YBw4t6A6ttlRtDY3wXEOsaIZiOWZoPZqSa/zYNkZHmcXW/Win5gdbS?= 

=  ?us-ascii?Q?clooH8zRhhLLvX0buENI j  GmMM5A7Gl/ 096VMGI6GlDlxPQ/ xTOCyO JlXnzPe?= 
=?us-ascii?Q?L7f J9rS J7xHMDkbUv5uefdc42q+SwN/SRJ7EpV5Bh5ZHncj l+SfEldkYznbu?= 
=?us-aseii?Q?vHmiRLP+MQN6Rx+/TX+a8FeIHzhF0UspYAXtt3mBAk8dzd35QOjqVLTOygxF?= 
=?us-ascii?Q?6Tl+9b9Ofm01LZLG7Wlyd8bx7jBC3L0uWphR2rYb5TXlqf5nnla6ehVrlRBH?= 
=?us-ascii?Q?G9pl82 t9vn3a8WzKrOW7/lbu2YpxOUl917BlmlVj  edBOmiyxcid®RyWoS100?= 
=?us-ascii?Q?DnOPxDMxxFN4YnZcSTc4RyT414tCBFAHX15RTlrxAH3dVbhydRhOk7p43zPZ?= 
=?us-ascii?Q?yWJncx4mwKr7FSdc/ZtiD?!= 

X-MS-Exchange-Transport-CrossTenantHeaders Stamped:  SA9PR09MB5168 
X-Organi z at ionHeaders Preserved:  SA9PR09MB5168 . namprd09.prod.outlook.com 
X-CrossPremisesHeadersFiltered:  CCCASV02 . CCOUNTY . com 
X-CrossPremisesHeadersFilteredBySendConnector :  CCCASV01 . CCOUNTY . com 
X-OrganizatibnHeadersPreserved:  CCCASV01 .CCOUNTY.com 

X-MS-Exchange-Transport-CrossTenantHeade.ps Stripped:  DM2GCC01FT006 . eop- 
gccOl .prod. protection . outlook.com 

X-Foref ront-Antispam-Report^i&trusted:  Cl? : 162 . 21 7 .184.79; CTRY :US; LANG: en; SCL:- 
1 ; SRV : ; I P V : CAL ; SFV : SKN; H : CCCASV0 1 . CCOUNTY . com; PTR : Inf oDomainNonexistent ; CAT : NONE ; SFTY : ; 
SFS:  (186003)  (166002)  (83380400001)  (356005)  (86362001)  (82310400002)  (19627405001)  (830804000 
01)  (81166007)  (5660300002)  (55016002)  (109986005)  (450100002)  (33656002)  (9686003)  (52536014)  ( 
2940100002)  (7416002)  (21480400003)  (8676002)  (26005)  (28085005)  (34756004)  (6506007)  (7696005) 
(336012)  (8936002)  (1096003)  ( 45080400Q02 ) ; DIR:INB; SFP : ; 

X-MS-Of f ice3 65-Filter ing-Correlation-Id-Prvs :  3cd88bl3-bc33-4696-34e3-08d81cf 6a3cl 
X-Microsof  t-Antispaitb^ti trusted:  SSL  :  0; 

X-Microsoft-Antispam-Message-Info-Original :  =?us- 

ascii?Q?gFqiaJZmTC0mLWk4LRgXhDniPyiiiqa/WHf/4axTrYiPmVu53Wj jWqfXA2sl?= 
=?us-ascii?Q?omlwpkygtY40TgU49EWCuN0eN+hRoyP/vqcj Wc6UupeNqhTe4rmW8+r2Q+Zl?= 
=?us-ascii?Q?N2znXaAvLRPQQyx5ea7uWVMlh9zZvlEIM3/5oDyQF82iQE2I j if f 46861UCr?= 
=?us-ascii?Q?ntGGTp8+JyerJkwrDf2zW9Rn6RsqOqlt/Nj:t5GwKLSNfIdHXOQZV0w417hM2'?- 
=  7us-ascii?Q?vQvku4wehAy7N3Qj  DJkf 0Q3eN6rmFyCwYn2YHVUDvXV6VSwr69GeCutDuNPc?= 
=?US-ascii?Q?9Lbea71GbUlyG/YWK7bEnceWhHJBB95Y/MZuNTr9qhsqbXBS./fi8AYIewIY81;ffe 
=?US-ascii?Q?ujtStQNT8tlQ2T0aX+gQYFl5HX/y0ip5JAaYZ6+GW71+n9lSmjqTkaIAh054?= 
=?us-ascii?Q?hPEkWFnrHB4HjtH9GUPtOS+FryJHFOXEHiiSb6vPQ2bwAW8DjE+xVHhzHlHj?= 
=?US-ascii?Q?TLBJCI47cDL6wKxuYZWSa+DvPZ5FSbc3qbLJVNWnFKzOjD0BO8VkL2WG98Fql?~ 

=  ?us-ascii?Q?YlqaRF51FJa3z j  KMsvXGKyUu/ yfRW+Nt9xeBDeQYj  j  sUpnRuH+f JHKXvhxM9?= 
=?us-ascii?Q?LsWl6nu4zaYA35f6tjM4tOK7Wi9z0reVcNHzKYCH5oi45LQHV+8Fi3+MA3N3f= 
=?us-ascii?Q?ZUtVLKWx/dmihfKWUs+4q8hkXd2UR8JE/2CPdqRjL7z/mndXWuWSwdPuPPSj?= 
=?us-ascii?Q?D+NxZvfgf rOUf 55UQ7WJhf lYdsGHUyJiSGj UUPTexcH8UHZlXxS9qDGXrWRq?= 
=?us-ascii?Q?+kTOrkiitZahg0mIPvY9aile03gAKUwcM6/0MnWIrkiowo0hFB6sAv/XuKPZx,i?i=i 
=?us-ascii?Q?/MLCbEtzZscIXRSyOVeAvS2dMwMPPAbxB3ivoOts8ghvfeX6iNib/DBc96uZ?= 
=?US-ascii?Q?LawIoMuFoi9PQIAh3rLJlkPiujtcJlCuz/vEkYQKOEXJOgJUQ2kFJLMOaTCG:?= 
=?us-ascii?Q?xZ9V6f 8QLFnVi6nq9SnzNghh4CLuR3FsmWd/K+SPQu+udweYxtreGeFaFavO?= 
=?us-ascii?Q?IB/Z62BXrcJn/BdR+WHKGuMSW6gqtlQsIYv5-lly8d2+vilL4aFUtSeFmeLiF?= 
=?us-ascii?Q?CiPmLPr04SWwKs/DoN3sdlXtDqsWN9WlLHEXBAEx3v0LK3HEfTRIkI9sIhMX?= 
=?us-ascii?Q?wFEvEZINweoU4GO91Fa9YTFlS9uHZavmiYXoKJ2jhRXKTVIc0vsTyEKWPYsW?= 


=?us-ascii?Q?OhL+iOCLD30MFSfVemx3t6sGOAoGcYZSIgXgZA=3D=3D?= 
X-MS-Exchange-Transport-CrossTenantHeadets stamped:  SA9PR09MB5230 
X-Organizatibntieaders Preserved:  SA9PE09MB5230 . namprdO 9 .prod. outlook . com 
X-CrossPremisesHeadersFiltered:  CCCASV02 . CCOUNTY . com 
X-CrossPremisesHeadersFilteredBySendConnector :  CCCASV01 . CCOUNTY . com 
X-OrganizationHeadersPreserved:  CCCASV01 . CCOUNTY . com 

X-MS-Exchange-Transport-CrossTenantHeadersStripped:  DM2GCC01FT005 . eop- 
gccOl .prod. protection . outlook.com 

X-Forefront-Antispam-Report-Untrusted:  CIP : 162 . 217 . 184 . 7 9; CTRY : US; LANG : en; SCL : - 
1 ;  SRVrflRV: CAL;  SFVjSKN;  H :  CCCASV01 .  CCOUNTY .  com;  PTR;  Inf oDomainNonexistent ;  CAT  iNQNE;  SFTY :  ; 
SFS :  (26005)  (6506007)  (336012)  (55016002)  (450100002)  (8936002)  (1096003)  (45080400002)  (214804 
00003)  (86362001)  (7416002)  (7696005)  (5660300002)  (52536014)  (28085005)  (34756004)  (2940100002 
)  (166002)  (33656002)  (83380400001)  (82310400002)  (186003)  (9686003)  (8676002)  (83080400001)  (81 
166007)  (19627405001)  (356005)  (109986005)  ;  ISIR:  INB;  SFP :  ; 

X-MS-Cf f i ce365-Fi 1 zering-Ccrrel ation-Id-Prvs :  c74b9e8a-9638-4e50-af 52-08d81 cf 6a8b4 
X-Microsof t-Antispam-Untrusted :  BCL : 0 ; 

X-Microsof  t-Ant.i  spam-Message-Infc-Crig.inal  :  =  ?us- 

ascii?Q?ATn/9yDj  sTyufQcLvFwtmp4bayBZOxlEY4Vu3mFfGw51mZnmn8Ud7  4rrOOcD?= 
=?us-ascii?Q?nwU7lM79KWKXrMFil0JfADwWfcsXhG90cUJi3lojD/uL35mDUZf7L7POrThF?= 
=?us-ascii?Q?VAtwzzealFoibDsdjsY2  6Xkn7CCijep071WomNzlP.3HGnteWR6NIjRrbJuWbt?= 

=  ?us-ascii?Q?gHO0ZouvsN/ rg7  0kX3t6/ 9CY2bs JUdcClfWzf kBlqCnUe5dc7vSwMAYj  2f 4r?= 
=?US-ascii?Q?gKzECmk96a85EAIgPvfWOWFWy/m/liy7QCD4LFp/5f9NNhuUETgij'bI6uAJJwf=! 

=  ?us-ascii?Q?Q7f f owh7ecgf cUViz6kasinW5X6DE5pYxXVKe9zZOFogU4Mj  sP02crWL6OUC?= 

=?us -as  cii?Q?rSYxeu+WcHtO/eb3IRkCZ  8  6uyzgSu7EG6.lt/rR2wpnbHaArmliyzlNVbSMoD4  ?= 

=  ?us-ascii?Q?WKXT+bMYf 5W2 j  PEQy7rCWEBuGonCGkdYkizuVDVFQwo j  6rm6ZLsWNLsRYlRM?= 
=?us-ascii?Q?sJ3t/vZc64sBSQH2EDOajZuS2011P3Wcjru242txK51ces8pI+aezS/jXv/V?= 
=?US-ascii?Q?D7BXy5EmlDn9ak/6UdTk+o/p,titFTBfLOTOyJh'YfE92H6n7qWiUb.oyFUrpyH?“ 
=?us-ascii?Q?y0Kf01Mb3Hg6VMa3WlGIFFixuIWpcPMpLiAZESasqbhpcvVh69EQ25ewlQod?= 
=?us-ascii?Q?mTlufHf 4sWbMvHM2  9STvfQSZ/BJ5EXGnlCpIbjqsm4gk3Copof S79oOYz+W?= 
=?us-ascii?Q?ZUcgLYKkXCo4reT0eGuVxMtYhiuP2CxdPS5V9cKZbYLpP/uXYbdTpUZzvSxK?= 
=?US-ascii?Q?qlTwRaQleMUl9VIybMa/SsICiFURB^E.lyuTMli!ErN3WSNvW3JsZ0g8iDlQPB?“ 
=?US-ascii?Q?aNNfuTyya9xAR6EDUKOcXZ'FX7TNXrZ0tV2b/j;LxyN/i;|;jM8mz5eki/ISYcsif» 
=?us-ascii?Q?yEqiY15Pv6hk8An3kmqUx87SrlhIwcy3FC9MpuvcQCTnlVByqOKWEZdXAe7A?= 
=?US-ascii?Q?  +  sgE5YXYY6An8zITwA9AFreJXV8kNikQ4W/c0mX4j  6D!31(ISyKHksVTkMl/Hl.f« 
=?us-ascii?Q?crQHp7e6nu0ErfnceohqsoEVkENDO5+3W+c6BfatQ77FN0WWWrChVcislwX9?= 
=?US-ascii?Q?hhdoCRnuVu3BYRNPGcrGdibmL3z619Wid3BuAR77uZq5fWWOUaiyG/zBtPKO?= 
=?US-ascii?Q?Kg8YdVNWC2x4rjBG965k/na9YStztOWhD8/wdL7U+Tr0/i5sFMNo75frln0r?- 
=?us-ascii?Q?G399gp86U6yH9SVmhdT/dFbfAUV09HNa63S6NA=3D=3D?= 
X-MS-Exchange-Transport-CtossTenantHeadersStamped:  MN2RR09MB5785 
X-OrganizationHeadersPreserved:  MN2PR09MB5785 . namprd09.prod.outlook.com 
X-CrossPremisesHeadersFiltered:  CCCASV02 .CCOtJNTY.com 
X-CrossPremisesHeadersFilteredBySendConnector :  CCCASV01 . CCOUNTY . com 
X-OrganizationHeadersPreserved:  CCCASV01 . CCOUNTY . com 

X-MS-Exchange-Transport-CrossTenantHeadersSiripped:  DM2GCC01FTQ07 . eop- 
gccOl .prod. protection . outlook.com 

X-Foref ront-Antispam-Report-Untrusted:  CIP: 1 62 ^ 21 7 . 184 . 7  9; CTRY : US ; LANG : en ; SCL: - 
1 ; SRV : ; I P V : CAL ; SFV : SKN; H : CCCASV0 1 . CCOUNTY . com; PTR : Inf oDomainNonexi stent ; CAT : NONE ; SFTY : ; 
SFS:  (45080400002)  (33656002)  (450100002)  (28085005)  (34756004)  (109986005)  (19627405001)  (7696 
005)  (9686003)  (55016002)  (5660300002) (6506007)  (166002)  (7416002)  (26005)  (8676002)  (214804000 
03)  (52536014)  (2940100002)  (83080400001)  (186003)  (356005)  (83380400001)  (86362001)  (8936002)  ( 
1096003)  (336012)  (82310400002)  (81166007);DIR:INB;SFP:; 

X-MS-Of fice3 65-Filter ing-Correlation-Id-Prvs :  3e809327-6045-4bb4-6fd5-08d81cf 6af 72 
X-Mi croscf r-Anti spam-Untrustec :  BCL : 0; 

X-Mi crcsof r-Anti spam-Message-Tnfo-Cri ginal :  =?us- 

ascii?Q?C6AUae6Y5nXxCBj A0e4HhMg8ns5f lQ0YsGkt4zabDIQ+TLdM+gWTa3dB3hLe?= 
=?us-ascii?Q?G3PQggSWuEQ2TxIKtgFjTrAwoIiLKqaWf JZvFRyxSmIu4zRfSF0giihxosYSH?“ 
=?us-ascii?Q?fioCFRfK8QHTAajOnsOPmxI61SoZxCJVA/elVn44/tGJeJlKmknLDZs4jwXb?= 
=?us-ascii?Q?Cx/6Bt68VlJHlnx654YFUixRzPTwMNQQVZz+NX7XVTVvL/YLM+8rv+to9va6f= 
=?us-ascii?Q? JoHz50TrPlKx0pcykAS7LoBQB02CqW4D0Z4LBCHIGptNUVyJIIO601gz4plv?= 
=?us-ascii?Q?lmNuxhJgk5LaSYliEzSJWEjeiwOu2EGOAOL/eIJMDf JT68Avo/d8l6/7oyRE?= 
=?US-ascii?Q?41bHu049DE2iAraqReVNyelsQ6WzuIge7iTy+sxg+Tw5L9Z3NMHwTRLljbKK?= 
=?us-ascii?Q?3sskNXxfBhlFBuhLbJYmU7HXW6UlxxxDYmdyFEbBlqeovpt3AqEI5vUiuQZF?= 
=?US-ascii?Q?jYjYL3TPvEllAl/LxZmvKSt2JLpld?NRj.JD/lyj9fTcg2Y0VGvo6OBmTPPGBf= 
=?us-ascii?Q?RQ9agIo6wVgHs3aDA9Yq3wzl0hyqj RqV4QcSl 6dnJ+QdTwNNG2XM043YWj kO?= 

■  ?us-ascii  ?Q?aO'I  mgB9u9  r  VsMo'l  j'l  cI.PsvDy/BHZeUobE/EJgl  wl  NrrGvrPVlIhC.l  CDFGsPd? 
=?US-ascii?Q?gLgglST5uWuGQkt/7Ex/bSbqqFiYlIIbIeElqSRyPs3UkwbufWG8DLXujY0cy?- 
=?us-ascii?Q?3AQ8 JINXvt JXRHDj v3eEVvZRIT0owIuEo0XZmcWBCBuG/ 3Yty5MdcvUbZa3i?= 


=?us-ascii?Q?aqz7t3wsX3aRYuQKyhap82BPEtCMFUa8Akk8xJDu+xiR+HmPZyXNaQwkJ6Mk?= 

■  ¥us-ascii  ?Q?Q  l  2  61  dYPzattYl  cl  A3m  I  VoFl  99HG33V2e  I  fVdxgul)8LXjz4gyBfY95SsqH8pY?- 
=?US-ascii?Q?XaAy/CAPrxzQtBKlwrQREA©i&E7kKXJXnKudgt4qGlN79dD36Hk8PwJF37jKriMr 
=?us-ascii?Q?CGlHV15Vs5fehe90KpA+xjXad2rLJ3hUax+xRTxALeSnw94r5wbq4MRv9el J?= 
=?us-ascii?Q?nVm4tbk3iZtJtw/Hdst8jhf JglQ3YqBNN4OB0lYXDpnddyRl=3D?= 
X-MS-Exchange-Transport-CrossTenantHeadersStamped:  BY5PR09MB5777 
X-OrganizationHeaders Preserved s  BY5PR09MB5777 . namprd09 .prod. outlook . com 
X-CrossPremisesHeadersFiltered:  CCCASV02 . CCOUNTY . com 
X-CrossPremisesHeadersFilteredBySendConnector :  CCCASV02 . CCOUNTY . com 
X-OrganizationHeaders  Preserved :  CCCASV02 .CCOUNTY.com 

X-MS-Exchange-Transport-CrossTenantHeadersStripped:  DM2GCC01FT008 . eop- 
gccO  1 .  prod  .protection.,  outlook ,  com 

X-Forefront-Antispam-Report-Untrusted:  CIP : 162 . 217 . 184 . 7 9; CTRY : US; LANG : en; SCL : - 
1;  SR¥:  ;I?¥::CAL;  SFV: SKN; H : CCCASV02 . CCOUNTY .  com; PTK:  inf oDomainttonexi stent; CAT: NONE; SFTY :  ; 
SFS :  (55016002)  (9686003)  (7416002)  (86362001)  (6506007)  (45080400002)  (336012)  (1096003)  (86760 
02)  (109986005)  (8936002)  (83380400001)  (186003)  (5660300002)  (81166007)  (34756004)  (28085005)  ( 
21480400003)  (26005)  (83080400001)  (450100002)  (166002)  (7696005)  (19627405001)  (294010000:2)  (8 
2310400002)  (33656002)  (52536014 ); DIR: INB; SFP : ; 

X-MS-Of fi ce365-Fi Itering-Correl at.i.on-Id-Prvs :  adedObf 7-036d-4al9^22 91-08d81cf 6d94b 
X-Microsof  t-Antispam.-Sntrusted::  'SCI*;:  0; 

X-Microsoft-Antispam-Message-Info-Original :  =  ?us- 

ascii?Q?4Tj04mXPijq3TMGOUlHsyy9Q3Ih96furc96jZXTiVz4C8GdiGNwM6Z¥yFkbJ?= 
=?us-ascii?Q?vtG3b7HBZZ+/ 4n+yuDCn7Nf 87yXWJMkX78f 2 JHAU7LAmQXYx2KwuFhvXBpGR?= 
=?us-ascii?Q?F52/SNZISWR8orxlOaW/lv+A5Slz7IilzPOcbwktXg+UYVWQKs9xflgQ6ABUGf= 

=  ?us-ascii?Q?WIPj  4WmzwwqGzO J06rZB10bFc09BY2PxXFJMFD80IWPFPcBZnuomirRTaRG+?= 
=?us-ascii?Q?eG5xtLSEE9PGxHE01DHDA9631Ri5hSo51/37zp0p0r8J7k/m+KWlSpidIwxU?= 
=?US-ascii?Q?bX8JnILqkKDl+478fKiub6M4S#SUNGJlSgvg7hV3G5fPbhtj+IASpFa03TYN?= 

=?us-ascii?Q?QS/Rdi8xOLf Ouuly4iRSyuOqj i j / fxf I5ZXVZEtNlMtsP/AAfuinzUxzCf Zo?= 
=?us-ascii?Q?e6lvYymXyUxUaUxlf Odu96RH/eKlBTvaGpR4GvtY8UC1308cqX5ZL3X7  3cw3)J~* 
=?us-ascii?Q?MJG3hSniKBPVSJ3zbCiL5T66s/af0il7N2Nb91u7Am9gLxZcZx5Qb71bVuWU?= 
=?US-ascii?Q?9hsFyWbTyUW938623UGJaTxdGZSp@DysXoK5GdsQY37JUD5b20WcmhueA6+G?= 
=?'US-ascii?Q?I719qotM+LfT2Vm/37brmncplih6mp88rnz¥Dl>rnlMr/rquQFfMEesOkO'tlEe1'‘=i 
=?us-ascii?Q?aoM8wkFRRAkUzl90gfdaywT+eGlY5y0z JVtn43+0 Jh2t+k6LEbbQXTxhInQx?= 
=?us-ascii?Q? yEn PIT + k 8 U 7  JFcBBl Zb 9 Q 0 gH S YyRr 6 V j  I SgcEx 9Xo JR5 a o a 0 3¥X7 TAqRxnK 
=?us-ascii?Q?HTaQ90c31RYAhOgQUgQClnrLfFx8qzSD/C7bh7ygx39AKUCmqxn5vG/t5tgl?= 
=?US-ascii?Q?NfiElAOkM63qwzK7aJUyjd6QObz jFtw8Xf JwXzp/xPkyr J41GXebxya8yfkJS?= 
=?us-ascii?Q?dOEpaQRUhFDUme¥ZbfUXhd34zqjndY8wpu36ZTTA51UUcPfChCnmQhU9F8hC?= 
=?us-ascii?Q?aZF8vWOcq8XwioHZZkOvxy7EDOikMg7AGe82DGp9MV6emldyqRbT9tTlwlWg?= 
=?us-ascii?Q?IVvMqpYXPX5p6uJ10vJm+eY+7NQYpU0jRJlWBng5kzcPYSA=3D?= 
X-MS-Exchange-Transport-CrossTenantHeadersStamped:  DM6PR09MB4591 
X-Organizationlieaders Preserved:  DM6PR09MB4591 . namprdO 9 .prod. outlook . com 
X-CrossPremisesHeadersFiltered:  CCCASV02 . CCOUNTY . com 
X-CrossPremisesHeadersFilteredBySendConnector :  CCCASV02 . CCOUNTY . com 
X-OrganizatiOBfieadersPreserved:  CCCAS¥02 .CCOUNTY.com 

X-MS-Exchange-Transport-CrossTenantHeadersStripped:  DM2GCC01FT005 . eop- 
gccOl .prod. protect ion, outlook. com 

X-Forefront-Antispam-Report-Untrusted:  CIP : 162 . 217 . 184 . 7 9; CTRY : US; LANG : en; SCL : - 
1;  SR¥.:  ;  £®¥:CAL;  SFV:  SKN;  H :  CCCAS¥02  .  CCOUNTY .  com;RTSiInf pDomaiiiNonexi stent;  CAT  :N0NE;SFTY :  ; 
SFS:  (19627405001)  (336012)  (109986005)  (7696005)  (34756004)  (52536014)  (8676002)  (83380400001) 
(28085005)  (86362001)  (186003)  (6506007)  (8936002)  (1096003)  (33656002)  (45080400002)  (21480400 
003)  (55016002)  (9686003)  (7416002)  (450100002)  (26005)  (166002)  (5660300002)  (2940100002)  (8116 
6007)  (82310400002)  (830804  00001);DIR:INB;SFP:; 

X-MS-Of fice365-Fllter:ing-Correlati6n-Id“Prvs :  96e9d464-2a42-4459-8f47-08d81cf8fb66 
X-Mi crosof t-Anti spam-Untrusted :  BCL : 0; 

X-Microsoft-Antispam-Message-Info-Original :  =?us- 

asci.i?Q?fMbAx91  9U/T3ZXxXb/I,Fmj  l'2oyBX  1  x\L4Ti;lkznbHV88MgmpmTgrf  l.qcV3dg? 
=?us-ascii?Q?X3sp/DEiLzzyLVf JdLGDQPx8IQXqWOw6oRACbG6hlIkOSxSvTy4vUEjB31y8?= 
=?us-ascii?Q?nHowU9e5L¥QBwHm5AOhbrrZyxAglrH6QXlj,ZXetPru39YXOFH3XVpO/6bOOnf=4 
=?us-ascii?Q?9ANCOGw05eolXysPHB/wgKBmpAj rN6Muy+k3evlpU8W8sAHbd2C8b20PT20p?= 

=  ?us-ascii?Q?YDHIZrKnAL4p3TQNrl9oW8IMdvo j  DCqdaKXR9kizl5pTf 0IIXYCsZH60hpDH?= 
=?US-ascii?Q?dliRhRYNzGNRYLW072T2THcoKNRJYIl+17o4  4uSXSUm91m9bUtd,FEza+AZ6/?=: 

=  ?us-ascii?Q?MMM9VO+HOm5TWidgDyPfMm9csPNsGhj  krgn2SZhTf 42D7koLIlmz/afwxpcb?= 
=?US-ascii?Q?Kf  jHaUKv.8  j  QhTno  j  igplNUi:yr6Wf6VSlZHAGh8juGEauN2ACBCuq7LWmzurH:fi“ 

=  ?us-ascii?Q?sBbhLlLiXiw7W6K7Fj  LwdhwX557govmEV5M2 JOkvrYf 2CG77  8MvGDN/TcGmp?= 
=?us-ascii?Q?Pk5TX9p6DDaarnuaS3dFZlEH2L/06/vblii¥Rnhkd9ICDlClgPZG:r8HcJ5eQs?= 
=?US-ascii?Q?CKMPNJzZWads9tbKWqbaIpWMB2/Wq08Cb38yfiA17yVQUY0y+VfGmGwZpKH2r?= 

=  ?us-ascii?Q?DGCa3U+T8rpcPxD6MLtviT8QmGAXQClwz JaDB7  OL3EOx4EaQ10m5sH8U5f Fc?= 


=?us-ascii?Q?Om/Sac+mS9DAMkfQWcnboTvOuxGY7L8TnjLpZ63Dm21b6hJiXV4rdndlWOkG?= 
=?us-ascii?Q?H+pmLd4vZO£’kj:  +  8LMLvTWgAyzGYpDM8haWrI98x2RQlK0yutj;O+F0j78J8wXf^ 
=?us-ascii?Q?8ik8pMas7p2MaHrWA9q2URG6+jOCnBqUw7nezqf7V2/TeTB8RKNtP8pHritt±fs? 
=?us-ascii?Q?rbCkzTlhpXcGAQTt8QtZu4RTD8alhVGVGaRAk7SwQf 9olVpCOLgZ35HD7F5H?= 
=?us-ascii?Q?Cz4nNPQKlgws49trP8ve89TpTR/F6BsaRuaVp4KiM2AmbnCJOoiJ/OLGlSdQ;?= 
=?us-ascii?Q? JhlvCsDpRQxaFVwlsGIOgc/M9NOP9BCp/ GsMOwmf iRH43L0=3D?= 
X-MS-Exchange-Transport-CrossTenantHeaders Stamped:  DM6PR09MB4838 
X-Organi z at ionHeaders Preserved:  DM6PR09MB4838 . namprd09.prod.outlook.com 
X-CrossPremisesHeadersFiltered:  CCCASV02 . CCOUNTY . com 
X-CrossPremisesHeadersFilteredBySendConnector i  CCCASV01 . CCOUNTY . com 
X-OrganizationHeadersPreserved:  CCCASV01 . CCOUNTY . com 

X-MS-Kxchange-Transporr-Cross'I  er.ant Header sStri  pped :  CY1GCC0TFT010  .  eop- 
gccOl .prod. protection . outlook.com 

X-Foref ror.r-Anti  spam-Heport :  CIP:1  62.21  7 .184 . 7 9>CTE,Y :  US; LANG-ren ;  SCL :  - 

1 ; SRV: ; 1J7: CAL; SFV : SKN ; H : CCCASV01 . CCOUNTY . com; PTR: Inf oDomaimNonexi stent ; CAT ;  NONE ; SFTY : ; 
SFS :  (166002)  (6506007)  (1096003)  (5660300002)  (8936002)  (26005)  (186003)  (82310400002)  (4501000 
02)  (83380400001)  (336012)  (7696005)  (21480400003)  (7416002)  (356005)  (55016002)  (45080400002)  ( 
109986005)  (86362001)  (28085005)  (33656002)  (83080400001)  (9686003)  (8676002)  (2940100002)  (525 
36014)  (34756004)  (81166007)  (1  9627405001 ) ; DIR: 1  KB; SF? : ; 

X-MS-Of f i ce365-Fi Irering-Correl ati.on-Id-Prvs :  46a6ab41-98fe-4465-7a07-08d81cfbl7cc 
X-Microsoft-Antispam:  BCL:0; 

X-Microscft-Anti spam-Mess age- Info :  =?Windows- 

12  52  ?Q?YKGNe4qFcHE+oGW9G+lkdGIEgOIKD+eI95kCWPame+ JrrUaXZZvgFoW0?= 
=?Windows-l252?Q?LMwkzttOv//9y9BqCzlleKX6wsNFiL5FXbbzOdIYok6LDRWR4H6upLKtf?= 
=?Windows-1252?Q?Q+3VOM86kRlsFSKlbPNic+qluZPFCFiezDmknwvATEoP16LOPVRkOONi?= 

=  ?Windows-12  52  ?Q?BtW0EElkirXADpA9 JVQqLuS/ JlnVIlsFpVY80tYZal3DvmbUVZ4GRqAl?= 
=?Windows-1252?Q?6r7X4CGI+XfB2AV)JNpzJYle+vlfQIMWrYy7yHuKYZ,2RZT7+A02TInqoJ?= 

=  ?Windows-12  52?Q?mxGwj  5PMdlk4syrhqo/c2GvldLWIpux/L4FUIzldT+RwlHCglk9vC8sn?= 
=?Windows-1252?Q?NzPmhWEvVBZVRVcCIcY7hm3N7e41EI/Tjt5M+0abxv/t67EE4FtbxxR+Y?= 
=?Windows-1252?Q?40pulGL3YwqQEyZYdJQpfl9aPoIU/wQWqHIzVh5FlUWYiqYYT9AQUriN?= 
=?Windows-1252?Q?Gg+qHuKDhPWs72f 3zNYMqmq2sN0YpsFPupL0xOuvSF5rfirlms06h8alq?‘- 
=? Windows-1252 ?Q?6wawt6o/PNsapivPicTKU3 5 92 T23tl/maQPdsra592qAXT90W8GyaRnm?= 
=?Windows-1252?Q?hZDWADE91hLL87VgBLQtEoL+dXh6hZ+KAD2/zDzEBaKtuHauHUm30Plc?= 

? W i  r, do w s - 1 2 5 2 ? Q ? n f  J H 6 H hN S f  V d  1  BN9/H4  0fS1  5 i  t  wHcJoGj  7ee64r.4  Yvxr,7HK84  1  I  7  F/Mp?r • 

=  ?Windows-12  52  ?Q?cf ZlOQznBCvulfmiLx/Aj yWoz4XclOJduf rY8dkuIUyPVyvZpGkfNUlm?= 
=?Windows-1252?Q?cJsPimfpBl43olkzXqkmJaff/7t0WA2i8yrNGV3KhdRWxJG0ccucQl7N?“ 
=?Windows-l|52?Q?auQtze/Sz+tD6QNDEQxEFRritlE,n.P99tay'JH8B3:pU;I)PY:szGaiBUOTMCGo4?= 

=  ?Windows-12  52  ?Q?lttbggxHFGylgnlF+eBrEx8DDkEngK6 j  CQPLS/PPwQT+ZLCZo+6+uG4 1?= 
=?Windows-1252?Q?ORKOcQmyZX6QrlM8zC5dK5Pfpa+2G6KOOJDiN06m8Zyyo4MzixfPMKMm?= 
=?Windows-1252?Q?4oalx47OiurBzlItUf0d/xiVBABLzUmDy/VomBEw0ZYQZEhDqXudlCV9?= 

=  ?Windows-1252?Q?UMDUvGlkWkSuotsei08u0vH9/TJRE\GE:nTr+3l  jOslFBQte  Jg3K/OgyVMA?= 
=?Windows-1252?Q?+TOCvl7Kw8h2Zjle716Jgssl7Akp35FpOfS2NWgFJk87VPoA8QkHVRlf?= 

=  ?Windows-12  52  ?Q?lXRrTCuQtoueolkM4 j  gsbD/ OOLRPA+zExj AXau8MlcIB9XllADJy6hfG?= 

?Windows-l  2527Q?/  FMi  yptXl.1  HvMHMmmGf r.mSAvl TVTHV1  I.WdQ  I  g  I  H08uga'I  d9WCQf u  I  M  I  B?  ’ 

=  ?Windows-12  52  ?Q?f rIArg=3D=3D?= 

X-MS-Exchange-CrossTenant-OriginalArrivalTime :  30  Jiln  2020  13:40:38.4698 
(UTC) 

X-MS-Exchange-CrossTenant-Network-Message-Id :  d60cf 752-ee33-4157-39f c-08d81cfb2cb5 
X-MS-Exchange-CrossTenant-Id:  8b4d55ae-6db4-4e05-a85c-59d6a256cd6e 

X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectinglp :  Tenantld=8b4d55ae-6db4- 
4e05-a85c-59d6a256cd6e;  Ip---  (1 62 .217.184.79]  ;  Helo=  [CCCASV01 .  CCOUNTY  ..com] 
X-MS-Exchange-CrossTenant-AuthSource :  CY1GCC01FT010 . eop- 
gccOl .prod.prdfcection.bytlook.com 
X-MS-Exchange-CrossTenant-AuthAs :  Anonymous 
X-MS-Exchange-CrossTenant-FromEntityHeader :  HybridOnPrem 
X-MS-Exchange-Transport-CrossTenantHeaders Stamped:  DM6PR09MB4 936 
X-OrganizationHeadersPreserved:  DM6PR09MB4936 . namprd09.prod.outlook.com 
X-CrossPremisesHeadersFiltered:  CCCASV02 .CCOUNTY. com 
X-OrganizationHeadersPreserved:  CCCASV02 . CCOUNTY . com 
X-CrossPremisesHeadersFilteredByDsnGenerator :  CCCASV02 .CCOUNTY . com 


Undeliverable:  Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law 
Enforcement  Data 


From:  Microsoft  Outlook 

<MicrosoftExchange329e71ec88ae4615bbc36ab6ce41 109e@cookcountyil.gov> 
To:  CCSO.INTEL@cookcountyil.gov,  Mary.Tamme@cookcountyil.gov, 

Wanda.Barnes@cookcountyil.gov,  Vincent.Gamez@cookcountyil.gov, 
Thomas.Shader@cookcountyil.gov,  Tangenise.Porter@cookcountyil.gov, 
Tamara.Levickas@cookcountyil.gov,  Samuel.Cory@cookcountyil.gov, 
Ronald.Prohaska@cookcountyil.gov,  Roger.Comer@cookcountyil.gov, 
Robert.Waller@cookcountyil.gov,  Robert. 0'Neill@cookcountyil.gov, 
Richard.Petersen@cookcountyil.gov,  Rex.Knaperek@cookcountyil.gov, 
Paul.Riley@cookcountyil.gov,  Paul.Huss@cookcountyil.gov, 
Nancy.Pavelka@cookcountyil.gov,  Michael.Ouan@cookcountyil.gov, 
Michael.Gomez@cookcountyil.gov,  Michael.Anton@cookcountyil.gov, 
Maurice.Cernick@cookcountyil.gov,  Matthew.Walsh@cookcountyil.gov 
Sent:  June  30,  2020  8:55:43  AM  CDT 

Received:  June  30,  2020  8:55:48  AM  CDT 

Attachments:  Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

Delivery  has  failed  to  these  recipients  or  groups: 

Marv.Tamme@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Wanda.Barnes@cookcountvil.qov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Vincent.Gamez@cookcountvil.aov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Thomas.Shader@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Tanqenise.Porter@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Tamara.Levickas@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Samuel.Corv@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Ronald.Prohaska@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Roqer.Comer@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Robert.Waller@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Robert.O'Neill@cookcountvil.qov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Richard.Petersen@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Rex.Knaperek@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Paul.Rilev@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Paul.Huss@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Nancv.Pavelka@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Michael.Ouan@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Michael.Gomez@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Michael.Anton@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 


configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Maurice.Cernick@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


Matthew.Walsh@cookcountyil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


The  following  organization  rejected  your  message:  CYlGCC01FT007.mail.protection.outlook.com. 


Diagnostic  information  for  administrators: 

Generating  server:  CCCASV02.CCOUNTY.com 

Mary.Tamme@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Flop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gccO  1 .  prod .  protection  .outlook.com]' 

Wanda.Barnes@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Flop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

Vincent.Gamez@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Flop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

Thomas.Shader@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Flop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gccO  1 .  prod .  protection  .outlook.com]' 

Tangenise.Porter@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Flop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

Tamara.Levickas@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Flop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

Samuel.Cory@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Flop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gccO  1 .  prod .  protection  .outlook.com]' 


Ronald.Prohaska@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

Roger.Comer@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

Robert.Waller@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

Robert.O'Neill@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

Richard.Petersen@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gccO  1 .  prod .  protection  .outlook.com]' 

Rex.Knaperek@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gccO  1 .  prod .  protection  .outlook.com]' 

Paul.Riley@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

Pa  u  I .  H  uss@cookcou  nty  i  I .  gov 
CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

Nancy.  Pavel  ka@cookcou  ntyi  I  .gov 
CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gccO  1 .  prod .  protection  .outlook.com]' 

Michael.Quan@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

Michael.Gomez@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

Michael.Anton@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

Maurice.Cernick@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 


Matthew.Walsh@cookcountyil.gov 

CYlGCC01FT007.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT007.eop- 
gcc01.prod.protection.outlook.com]' 

Original  message  headers: 

Received:  from  CCCASV02.CCOUNTY.com  (10.124.40.40)  byCCCASV02.CCOUNTY.com 
(10.124.40.40)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
ci#ft@*-*F£S  SO&fiS;  RSA_WIT»  AES_128_GCM_SHA256)  id  15.1.1261.35;  The,  30  Jun 
2020  08:40:40  -0500 

Received:  from  GCC02-BL0-obe.outbound.protection.outlook.com  (10.124.186.250) 
byCCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 
15.1.1261.35  via  Frontend  Transport;  Tue,  30  Tun  2020  08:40:40  -0500 
Received:  from  DM6PR09CA0036.namprd09.prod.outlook.com  (2603 : 10b6 : 5 : 160 : : 49) 
by  MN2PiR09MB4843.namprd09.prod.outlook.com  (2603:10b 6:208:21b: :22)  with 
Microsoft  SMTP  Server  (version-TI.Sl _2 , 

cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3153.20;  Tue,  30  Jun 
2020  13:40:38  +0000 

Received:  from  CY1GCC01FT010 . eop-gccOl .prod. protection . outlook.com 
(2a01: 111 : f 400 : 7d02 : :208)  by  DM6PR09CA0036. outlook. off ice365 . com 
(2603 : 10b6 : 5 : 160 : : 49)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3131.21  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:40:38  +0000 
Authentication-Results:  spf=softfail  (sender  IP  is  162.217.184.79) 
smtp .mailfrom— cookeountyil , gov;  cookcountyil , gov;  dkinp=none  (message  not 
signed)  header . d=none; cookcountyil . gov;  dmarc=fail  action=none 
header . f rom=cookcountyil . gov; 

Received-SPF:  SoftFail  (protection.outlook.com:  domain  Of  transitioning 
cookcountyil.gov  discourages  use  of  162.217.184.79  as  permitted  sender) 
Received:  fromCCCASV01.CCOUigTY.com  (1  62.217.1  84.79)  by 
CYlGCC01FT010.mail.protection.outlook.com  (10.97.0.149)  with  Microsoft  SMTP 
Server  (version^TLS1_2 ,  cipher=TLS  BC'9REjRSA_WITH_AES_128_GCM_SHA256)  id 
15.20.3131.20  via  Frontend  Transport;  Tue,  30  JUn  2020  13:40:37  +0000 
Received:  from  CCCASV02.CCOUNTY.com  (10.124.40.40)  by  CCCASV01.CCOUNTY.com 

(10.124.40.39)  with  Microsoft  SMTP  Server  (versibh=TLSl_2, 

cipher=TLS_ECDHE_RSA_WITH_AES_12 8_GCM_SHA2 5 6 )  id  15.1.1261.35;  Tue,  30  Jun 
2020  08:40:05  -0500 

Received:  from  GCC02-BL0-obe.outbound.protection.outlook.com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(versish-TLSlJI*  cipher=TbS_ECDHE_RSA_Wtf|i_AES_12 8_GCM_SHA2 56 )  id 
15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:40:05  -0500 
Received:  from  MWHPR09CA0045.namprd09.prod.oUtlook.com  (2603 : 10b6 : 300 : 6d: : 31) 
by  CH2PR09MB4588.namprd09.prod.outlook.com  (2 603 : 10b6 : 610 : 65 : : 13 )  with 
Microsoft  SMTP  Server  (version=TLSl_2 , 

cipher-TLS_ECBHE_RSA_WITHJilg_256_GCM_SHA384)  id  15.20.3131  .21;  Tue,  30  Jun 
2020  13:40:03  +0000 

Received:  from  DM2GCC01 KT005 . eop-gccOl .prod. projection .outlook . com 
(2a01:lll:f400:7d01: :201)  by  MWHPR09CA0045.outlook.office365.com 
(2603 : 10b6 : 300 : 6d : : 31 )  with  Microsoft  SMTP  Server  (vers  ion-TLSI  _2 , 
cipher*=TlS_EGBHi_RSA_WITH_AE5_2.56_GCM_SHA384),  id  15.20.3131  .21  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:40:02  +0000 
Authenticatioh-ResUlts-Original :  spf  softfail  (sender  TP  is  162.217.184.79) 
smtp ,mailfrom=cookcountyil . gov;  cookcountyil.gov;  dkim=none  (message  not 
signed)  header .  d=none;  cookcountyil .  gov;  dmarc=fail  actiori-none 
header . f rom=cookcountyil . gov; 

Received-SPF:  SoftFail  (protection.outlook.com:  domain  of  transitioning 
cbokeountyil.gov  discourages  use  of  1 62. 2 17. 184. 79  as  permitted  sender) 
Received:  from  CCCASV02.CCOUNTY.com  (162.217.184.79)  by 
DM2GCC01FT0Q5 .maii.protectibn. outlook. com  (10.97.3.0)  with  Microsoft  SMTP 
Server  (version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 
15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:40:02  +0000 
Received:  fromCCCASV02.CCOUl.®Y.com  (10.124.40.40)  byCCCASV02.CCOUNTY.com 

(10.124.40.40)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipKer=TLS_ECEHE  RSA_WITH_AES_128_GCM_SHA256)  id  15.1.1261.35;  Tue ,  30  Jun 
2020  08:24:57  -0500 


Received:  from  GCC02-DM3-obe.outbound.protection.outlook.com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(version=TLSl_2*,  cipheh^TSB_ECBREJRSAJWITiB_AES_128_GCM_SHA256)  id 

15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:24:57  -0500 
Received:  from  BN6PR09CA0050.namprd09.prod.outlook.com  (2603 : 10b6 : 404 : 7a : : 12) 
by  SA9PR09MB4638.namprd09.prod.outlook.com  (2603 : 10b6 : 806 : 4f : : 10)  with 
Microsoft  SMTP  Server  (version-- -TLS  1_2. , 

cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3131.21;  Tue,  30  Jun 
2020  13:24:52  +0000 

Received:  from  DM2GCC01 KT008 . eop-gccOl .prod.protectioh.oiitlook.com 
(2a01 : 111 : f 400 : 7d01 : : 2 0 7 )  by  BN6PR09CA0050.outlook.office365.com 
(2603  : 10b6  :  4  04  :  7a:  :  12 )  with  Microsoft  SMTP  Server  (version-  TI,S1_2 , 
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3153.20  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:24:52  +0000 
Aurhenti car ion-Results-Ori ginal :  spf— soft  fail  (sender  IP  is  162.217.184.79) 
smtp ,mailfrom=cookcountyil . gov;  cookcountyil.gov;  dkim=none  (message  not 
signed)  header. d— none; cookcountyil.gov;  dmarc=fail  actioh'^gi-dne 
header . f rom=cookcountyil . gov; 

Received-SPF:  SoftFail  (protectioh.outlook.com:  domain  of  transitioning 
cookeountyil.gov  discourages  use  of  162.217.184.79  as  permitted  sender) 
Received:  from  CCCASV02.CCOUNTY.com  (162.217.184.79)  by 
DM2GCC01 FT008 .mail .protection . outlook . com  (10.97.3.193)  with  Microsoft  SMTP 
Server  (version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 
15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:24:51  +0000 
Received:  from  CCCASV02.CCOUNTY.com  (10.124.40.40)  by  CCCASV02.CCOUNTY.com 
(10.124.40.40)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher«Tl,S_EC&HE_RSA_WITl_AES_128_GCM_SHA256)  id  15.1.1261.35;  Tue,  30  Jun 
2020  08:09:46  -0500 

Received:  from  GCC02-BL0-obe.outbound.protectioh.pUtlook.com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(versich-TLSl_2 ,  cipher=TiS_ECDHE_RSA_Wl:T$_AES_128_GCM_SHA256)  id 

15.1 .1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:09:46  -0500 
Received:  from  CY4PR09CA0093.namprd09.prod.outlook.com  (2 603 : 10b6 : 903 : c7 : : 31 ) 
by  MN2PR09MB5515.namprd09.prod.outlook.com  (2603 : 10b6 : 208 *211 : : 20)  with 
Microsoft  SMTP  Server  (version=TLSl_2 , 

c iph e r -  -TJ. S_BCDH3_R S A_W  I  TH_AES_256_GCM_SHA384  )  id  15.20.31  53.20;  Tue,  30  Jun 
2020  13:09:44  +0000 

Received:  from  DM2GCC01FT007 . eop-gccOl .prod. protection . outlook.com 
(2a01 : 111 : f 400 : 7d01 : : 200)  by  CY4PR09CA0093 . outlook. off ice365 . com 
(2603 : 10b6 : 903 : c7 : : 31)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
ciphet-TfS__ECDHE_RSA_WITH_AES_256_GCM_SHA384)  id  15.20.3131 .23  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:09:44  +0000 
Authentication-Results-Original :  spf=softfail  (sender  IP  is  162.217.184.79) 
smtp. mailf roa^ddekeountyfi. gov;  cookcounty.il  .gov;  dkim-ndne  (message  not 
signed)  header . d=none; cookcountyil . gov;  dmarc=fail  action=none 
header . from- -cookcountyil . gov; 

Received-SPF:  SoftFail  (protection.outlook.com:  domain  of  transitioning 
cookcountyil .gov  discourages  use  of  1 62. 217. 184. 79  as  permitted  sender) 
Received:  from  CCCASV01.CCOUNTY.com  (162.217.184.79)  by 
DM2GCC01FT007.mail.protection.outlook.com  (10.97.3.159)  with  Microsoft  SMTP 
Server  (versioh^Tf@l_2 ,  ciphen-TLS_^&E3R_RSA_WlTH_AES_128_GCM_SHA256)  id 
15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:09:44  +0000 
Received:  fromCCCASV02.CCOUNTY.com  (10.124.40.40)  byCCCASV01.CCOUNTY.com 
(10.124.40.39)  wi'fh  Microsoft  SMTP  Server  (versidn=TLSl  2, 

cipher=TLS_ECDHE_RSA_WITH_AES_12 8_GCM_SHA2 5 6 )  id  15.1.1261.35;  Tue,  30  Jun 
2020  08:08:44  -0500 

Received:  from  GCC02-BL0-obe.outbound.protection.outlook.com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 

15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:08:44  -0500 
Received:  from  CY4PR09CA0074.namprd09.prod.outlook.com  (2603 : 10b6 : 903 : c7 : : 12 ) 
by  MW2PR0901MB3819.namprd09.prod.outlook.com  (2 603 : 10b6 : 302 : 6 : : 17 )  with 
Microsoft  SMTP  Server  (version;=TLSl_2-, 

cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3131.24;  Tue,  30  Jun 
2020  13:08:36  +0000 

Received:  from  DM2GCC01 FT007 . eop-gccOl . prod. protection . out look. com 
(2a01:lll:f400:7d01: :201)  by  CY4PR09CA0074.outlook.office365.com 


(2603 : 10b6 : 903 : c7 : : 12 )  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher-TiS_BCnHE_RSA_WITH_AES_256_GCM_SHA384)  id  15.20.3153.20  via  Frofrfcend 
Transport;  Tue,  30  Jun  2020  13:08:34  +0000 
Authentication-Results-Original :  spf=softfail  (sender  IP  is  162.217.184.79) 
smtp.mai  1  f rom-cockcountyil  .gov;  cookcounty.il  .gov;  dkim—npne  (message  not 
signed)  header . d=none; cookcountyil . gov;  dmarc=fail  action=none 
header . f rom—ccokcountyil . gov; 

Received-SPF:  SoftFail  (protection.outlook.com:  domain  of  transitioning 
Cookcountyil.gov  discourages  use  of  162.217.184.79  as  permitted  sender) 
Received:  fromCCCASV01.CC0USTY.com  (162.217.184.79)  by 
DM2GCC01FT007.mail.protection.outlook.com  (10.97.3.159)  with  Microsoft  SMTP 
Server  (versioftwTLSl_2 ,  ciphet-TLS ^&DSE_RSA_WITH_AES_128_GCM_SHA256)  id 
15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:08:34  +0000 
Received:  fromCCCASV02.CCOUSTY.com  (10.124.40.40)  byCCCASV01.CCOUSTY.com 
(10.124.40.39)  with  Microsoft  SMTP  Server  (versi0n=TLSl  2, 

cipher=TLS_ECDHE_RSA_WITH_AES_12 8_GCM_SHA2 5 6 )  id  15.1.1261.35;  Tue,  30  Jun 
2020  08:08:33  -0500 

Received:  from  GCC02-BL0-obe.outbound.protection.outlook.com  (10.124.186.250) 
by  CCCASV02 .CCOUNTY . com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(version  J’T,S1_2 ,  cipher=TLS_EC0flE_RSA_WITl_AES_12 8_GCM_SHA2 56)  id 
15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:08:32  -0500 
Received :  from  BI.2PR09CA0034 .namprd09.prod.outlook.com 
(2a01 : 111 : e400 : c743 : : 4 4 )  by  BY5PR09MB5969.namprd09.prod.outlook.com 
(2603  : 10b6 :  a03  :  24f :  :  15 )  with  Microsoft  SMTP  Server  (verSi6in=TLSl_2 , 
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3131.23;  Tue,  30  Jun 
2020  13:08:30  +0000 

Received:  from  DM2GCC01 FT005 . eop-gccOl .prod. protection . outlook . com 
(2a01:lll:f400:7d01: :207)  by  BL2PR09CA0034.outlook.office365.com 
(2a01 :  111 : e400  :  c743  :  :  44 )  with  Microsoft  SMTP  Server  (vers i.cn-TLSl_2 , 
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3131.21  via  Frontend 
Transport;  Tue,  30  Jun  .2020  13:08:29  +0000 
Authentication-Results-Original :  spf  softfail  (sender  TP  is  162.217.184.79) 
smtp ,mailfrom=cookcountyil . gov;  cookcountyil.gov;  dkim=none  (message  not 
signed)  header  .d=none;  cookcountyil.gov;  dmarc=fail  actiofi'=ftdne 
header . f rom=cookcountyil . gov; 

Received-SPF:  SoftFail  (protection, outlook. com:  domain  of  transitioning 
cookc0untyil.gov  discourages  use  of  1 62 .21 7 . 1 84 . 79  as  permitted  sender) 
Received:  from  CCCASV01.CCOUNTY.com  (162.217.184.79)  by 
DM2GCC01FT005 .maii,i.protection. outlook . com  (10.97.3.0)  with  Microsoft  SMTP 
Server  (version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 
15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:08:29  +0000 
Received:  from  CCCASV02.CCOUNTY.com  (10.124.40.40)  by  CCCASV01.CCOUNTY.com 
(10.124.40.39)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher=TLS_ECD3fi_RSA_WITH_AES_128_GCM_SHA256)  id  15.1.1261.35;  Tue,  30  Jun 
2020  08:08:19  -0500 

Received:  from  GCC02-DM3-obe.outbound.protection.oUtlOok.com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(version--Tl.,S1_2 ,  cipher^TLS_ECBHE_RSA_WlTi_AES_12  8_GCM_SHA2  56)  id 
15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:08:19  -0500 
Received:  from  BL0PR0901CA0023.namprd09.prod.outlook.com 
(2603:1 Ob 6:208:lc0: : 33)  by  BYAPR09MB312 6 . namprdO 9 .prod. outlook . com 
(2603 : 10b6 : a03 : 9a : : 14 )  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher=TliSMECDJSE__RSA_WIT|l^;AES_2 5 6_GCM_SHA3 8 4 )  id  15.20.3131.24;  Tue,  30  Jun 
2020  13:08:17  +0000 

Received:  from  DM2GCC01FT006 . eop-gccOl .prod. protection . outlook.com 
(2aQl : 111 : f 400 : 7d01: :202)  by  BL0PR0901CA0023.oUtlook.office365.com 
(2603 : 10b6: 208 : IcO : : 33)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher-TLS_ECiK£JE__RSA_WITH_AES_256_GCM_SHA384)  id  15.20.3131.21  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:08:16  +0000 
Authentication-Results-Original :  spf=softfail  (sender  IP  is  162.217.184.79) 
smtp .mailf rgm—cookcountyil. gov;  cookcountyil, gov;  dkia^none  (message  not 
signed)  header . d=none; cookcountyil . gov;  dmarc=fail  action=none 
header . from -cookcountyil . gov; 

Received-SPF:  SoftFail  (protection.outlook.com:  domain  of  transitioning 
cookcountyil.gov  discourages  use  of  1  62. 2. 17. 184. 79  as  permitted  sender) 
Received:  from  CCCASV01 . CCOUNTY . com  (162.217.184.79)  by 
DM2GCC01FT006.mail.protection.outlook.com  (10.97.3.107)  with  Microsoft  SMTP 


Server  (version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 
15.20.3131.2Q  via  Frontend  Transport;  Tue,  30  J'un  2020  13:08:16  +0000 
Received:  from  CCCASV02.CCOGNTY.com  (10.124.40.40)  byCCCASV01.CCOUNTY.com 

(10.124.40.39)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 

cipher =TLS_ECDHE  RSA_WITH  AES_128_GCM_SHA256)  id  15.1.1261.35;  The,  30  Jun 
2020  08:08:12  -0500 

Received:  from  GCC02-DM3-obe . outbound . protection . outlook . com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 
15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:08:12  -0500 
Received:  from  BN3PR09CA0059.namprd09.prod.outlook.com  (2 603 : 10b6 : 400 : 3 : : 27 ) 
by  BYAPR09MB3237.namprd09.prod.outlook.com  (2603 : 1 0b6 : a03 :a2 ;  :22)  with 
Microsoft  SMTP  Server  (version=TLSl_2 , 

cipher=TLSMECDHE__RSA_WITR__AES_256_GCM_SHA384)  id  15.20.3131  .24;  Sue,  30  Jun 
2020  13:08:10  +0000 

Received:  from  DM2GCC01FT009 . eop-gccOl .prod. protection . outlook.com 
(2aQl:lll : f 400 : 7d01: :204)  by  BN3PR09CA0059 . outlook. of fice3 65 .com 
(2603 : 10b6 : 400 : 3 : : 27 )  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher=TUS_ECD.fffi_RSA_WITH_AES_256_GCM_SHA384)  id  15.20.31  53.20  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:08:10  +0000 
Authentication-Results-Original :  spf=softfail  (sender  IP  is  162.217.184.79) 
smtp .mailf rom— ©bbkcountya,! . gov;  cookcountyil . gov;  (message  not 

signed)  header . d=none; cookcountyil . gov;  dmarc=fail  action=none 
'header . f rcm-eookcountyil . gov; 

Received-SPF:  SoftFail  (protection.outlook.com:  domain  of  transitioning 
cookcountyil.gov  discourages  use  of  162.217.184.79  as  permitted  sender) 

Received :  from  CCCASV02 . CCOUNTY .com  ( 162 .217.1  84.79)  by 
DM2GCC01FT009.mail.protection.outlook.com  (10.97.2.68)  with  Microsoft  SMTP 
Server  ( versioa£#6gl_2 ,  cipher=TLS  CEtDR£_RSA_WITH_AES_128_GCM_SHA256)  id 
15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:08:09  +0000 
Received:  fromCCCASV02.CCDUSTY.com  (10.124.40.40)  byCCCASV02.CCOUNTY.com 

(10.124.40.40)  with  Microsoft  SMTP  Server  (vers ion1  TI,S1_2 , 

cipher=TLS_ECDHE_RSA_WITH_AES_12 8_GCM_SHA2 5 6 )  id  15.1.1261.35;  Tue,  30  Jun 
2020  08:07:51  -0500 

Received:  from  GCC02-BL0-obe.outbound.protection.outlook.com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
( ve  r:  s  1  on:  -TLS  1_2 ,  cipher=sTlfS_ECDBE_RSA_WiTft_AES_12  8_GCM_SHA2  56)  id 
15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:07:51  -0500 
Received:  from  CH2PR09MB4 4  91  . r.amprd09  . prod  . outlook .  com  (2603  : 10b6 :  610  :  36  :  :  19) 
by  CH2PR09MB4395.namprd09.prod.outlook.com  (2603 : 10b6 : 610 : 6d: : 18)  with 
Microsoft  SMTP  Server  (version~TLSl_2 , 

cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3131.21;  Tue,  30  Jun 
2020  13:07:47  +0000 

Received:  from  CH2PR09MB4491.namprd09.prod.outlook.com 
(  [fe80 : : 54b4 : la30 : 151b : 810f ] )  by  CH2PR09MB4  4  91 . namprd09.prod.outlook.com 
( [fe80: :54b4:la30:151b:810f%5] )  with  mapi  id  15.20.3131.027;  Tue,  30  Jun  2020 
13:07:47  +0000 

From:  "CCSO  Intel  (Sheriff)"  <CCS0. INTELgcookcountyil . gov> 

Subject:  Pass  Through  (U//F0U0)  Criminal  Hackers  Target  US  Law  Enforcement 
Data 

Thread-Topic j.lfass  Through  ■-  (U//F0U0)  Criminal  Hackers  Target  US  Law 
Enforcement  Data 

Thread-Index:  AdZ0UZ'RVrVUDcfOlTiiWh3YE0iFXiAAjZyaaAAALg8I= 

Date:  Tue,  30  Jun  2020  13:07:45  +0000 
Message-ID: 

CCR2PR0 9MB4491 9AB3DDCF48A1 DC9A721BF56FO0CH2PRO9MB4491  . namprdO 9 .prod. outlook . com> 
References:  <LYRIS-103 90 995 6-14 1184 6-2020 . 06 . 29-15 . 13 . 38— isp-les- 

north  #1 ists . i 1 1 inois . gcv@ lists . Illinois . gov>, <CH2PR09MB44  918DBCA153§E4l8B6FBl7FF56F0@CH 
2PR09MB4491 . namprd09.prod.outlook.com> 

In-Reply-To : 

<CR2PR0 9MB44918DBCA1539E418B6FBl7FF56F0@CH2PR09MB4491.namprd09.prod.outlook.com> 

Accept-Language :  en-US 

Content-Language:  en-US 

X-MS-Has-Attach :  yes 

X-MS-TNKF-Cor re  laior: 

Authentication— Results-Original :  cookcountyil, gov;  dkim-nona  (message  not 
signed)  header . d=none; cookcountyil . gov;  dmarc=none  action=none 


header . f rom=cookcountyil . gov; 
x-originating-ip:  [162 .217 . 184 .194] 
x-ms-publictraf f ictype  ;  Email. 

X-MS-0ffice3 65-Filter ing-HT :  Tenant 

X-MS-Of  f  ice3  65-Filtef.i.hg-Corr.e,latA0:ii”'ld :  4e80628d-db4  6-4cl3-8d96-08d81cfb2c4  9 
x-ms-traf f ictypediagnostic : 

CH2RR09MB4395 : | BYAPRO 9MB  3  2. 3  7 : | BYAPR09M33126 : | BY5PR09MB5969 : | MW2 PR0901 MB381 9: |MN2PR09MB5 
515: | SA9PR09MB4638 : | CH2PR09MB4588 : | MN2PR09MB4843 : 
x-ms-oob-tlc-oobclassif iers : 

OLM: 9508 ; OLM: 9508;OLM: 9508;OLM: 9508;OLM: 9508;OLM: 9508;OLM: 9508;OLM: 9508;OLM: 9508; 
X-Microsof t-Antispam-Untrusted :  BCL : 0 ; 

X-Mierosof  t-A,ntispam-Mes  sage-inf  o_0rigihal : 

dorE2  6 j V2iSCAAZPeOVhoLD94Hv4kxz7P8odY90Qx9txS684f FRvsQrQNNuMcw5 j  3CXAvxwJ6RKVNhma4waBTSV 
\I)Gxp/cmBk4EK1  mmOJLi  gt'qP/p5X3KfbKvh7 1  SXKcuXNUZ'E-lkV  t  zSCDOeoSmi  aj  i  r,OJW7  JVM  I  LK1830P1  /aGzKO 
q6bOCrceql  axl  nk4eWaDTHoAO  I  y'r.54  /  JAVk4Vrimq/BMj  1  4mSCAvqOgQu1  CSA3SG/epzZtTashTb6cRV\:MQgeo  I  r 
JRKNCeaiFc3HMFzVIRVpFATyE6RE60VqdV0G2K5Psnu0/NhyqisQzWRtPZnKnQE65W6iRiiEbtg0bqS5Zzmj  cRR 
H  4  CGvuJFl.3t.Gl  yM- 

X-Forefront-Antispam-Report-Untrusted:  CIP : 255 . 255 . 255 . 255 ; CTRY :; LANG : en; SCL : - 
1 ; SRV : ; LRV :NLI ; SFV : SKI ; H : CH2PR0 9MB4  4  9 1 . namprdO  9 . pr od . outlook .com; PTR : ; CAT : NOSE ; SFTY : ; SF 
S: ;  DIR:- INB  ;SFP:; 

x-ms -exchange -ant ispam-messagedat a : 

If  yUdGNo6Rf  5k?/RudyGbEyoz  I  NqqBXdgwdr JdYqr',14KGO77nPkGt,rCiHAy0f'LT)HpKf  au4  H'l  sKcP4KPTjB/.t0qc 
MOswESqf 7  6XMqi53/H/ f tP7B223MsFZ9fg5VOxHvc32BClwGPDW+ JR3ilqP6YkWVZTuxClUHYV/m3qO/WA7  zFrn 
qlHGYz/BQ9xQPFzN9ySyJCGd  I  j  9svK3rmr,r.7n  j  YATQdwBhm/L/06zYHtkcQuXCphogmV5:-  wxhteYsDQl  8Z9'I,phi 
UGfnt04ZLeJKhaQlTC86oFyonuAQ8DSt4ZyaYeVXcbN0uyrBFtWcyDVzIMi6RwmDU4aA8eX2yeHjnQlngAXfb6w 
xmTfCdhMIo3Kbla8ErnlLS56npY6/GW/CGnflqCGoLMKgNMBwrDrqOyAnvMuo6sEXA/bdkPEDSJD8JxHzl3yOp7 
4  YkgohRwqBYld6GvNdl)vR?Jel2. 1  zDacv  I  MFwLl  jmdkuTxYJKykmI,dGp8GhPI.73qvrmH'bfbAye08sP 
x-ms-exchange-transport-f orked :  True 
Content-Type :  multipart/mixed; 

boundary="_004_CH2PR09MB44919AB3DDCF48AlDC9A721BF56F0CH2PR09MB4491namp_" 
MIHE-Versi,b®:;  1.0 

X-MS-Bxchar.ge-Transport-CrossTenancHeadersStamped:  CH2PR09MB4395 
X-Organi z at ionHeaders Preserved:  CH2PR09MB4395 . namprd09.prod.outlook.com 
To:  Undisclosed  recipients:; 

Return-Path :  CCSO . INTEL@cookcountyil . gov 

X-Cross Premises Headers Filtered :  CCCASV02 .CCOUNTY.com 

X-Cross  Premise s Header sh'-i  1  ceredBySer.dConr.eccor :  CCCASV02  .  CCOUNTY  i com 

X-OrganizationHeadersPreserved:  CCCASV02 . CCOUNTY . com 

X-BOPAttri butecMessage :  7 

X-MS-Exchange-Transport-CrossTenantHeadersStripped:  DM2GCC01FT009 . eop- 
gccO  1 .  prod .  pro  tection.  ./outlook ,  com 

X-Forefront-Antispam-Report-Untrusted:  CIP : 162 . 217 . 184 . 7 9; CTRY : US; LANG : en; SCL : - 
1 ; SRV : ; IPV: CAL; SFV: SKN; H : CCCASV02 . CCOUNTY . com; PTR: Inf oDomainNonexistent; CAT : NONE; SFTY : ; 
SFS :  (2940100002)  (34756004)  (356005)  (186003)  (86362001)  (109986005)  (166002)  (33656002)  (82310 
400002)  (336012)  (28085005)  (6506007)  (26005)  (45080400002)  (5660300002)  (450100002)  (9686003)  ( 
83380400001)  (21480400003)  (81166007)  (7696005)  (83080400001)  (7416002)  (55016002)  (1962740500 
1)  (52536014)  (1096003)  (8676002)  (8936002);DIR:INB;SFP:; 

X-MS-Of  f  i  ce365-Filuering-Cor.r:el  ation-Id-Prvs :  2b67f  42c-4bba-4f  30-21 6e-08d81cf  695cl 
X-Microsof  t^Antispam-UntfUsted:  BQtsji  0; 

X-Microsoft-Antispam-Message-Info-Original :  =?us- 

ascii  ?Q?2YnnqSl  PMKSaQYCuMk4UvXH9.r7cmUHgf  rE;Z3E/GUi  6pKQ01 1 1byJ'qgyrsI.Zd? 

=  ?us-ascii?Q?78Cg9LxJLN+Bnf 3NxRLRT j  8 JOg3VAsyCJNaEROhoFEfHX9fpkdaPrlMx+mJl?= 
=?US-asCii?Q?e9MpnKYW8PhlNs067dxgePaRIYe2c6kZmYRpeZoeAYl JcAduSlkeyRBSyG0a?= 
=?US-ascii?Q?a2SMxC+3UeFElmkgQCPNIFP:zGqL8YfqQxCQ7vllHCfq504taR:2e7NinAyJNm?= 
=?us-ascii?Q?o5T2B5LWnOVsaDR4//C2Q+ZmM8uP2gOT5IY5LQneJ4vOj7KYkHv5o+/i/Pht?= 
=?us-ascii?Q?FLeLiML+TU2bvQ9jD5kxUl2n0uss41dj3ZwhFkNv97LDURqrFNrakPXn+vRI?- 
=  ?us-ascii?Q?AIhKOjN6GIr j  TtSaG/KOm/2 j  0RUaAPHeF7H+F/2f JHV5/lbBFS9Yug7  sUTap?= 
=?us-ascii?Q?dQ28QVEem2n6NClEf0uWTM9sSqnAldhyDUTmAKaNXqSjfSuMQXHHw+wF33xC:|= 
=?us-ascii?Q?QIdypmtG/Y9+HoMevu+6Vb5XStpEgNTQaxsKsOo28j j rT/A2 j HtTpTDo7u6R?= 
=?us-ascii?Q?5iWPFJzMlC6AM3HX/V/AC7+XIMgJ6a+MsnqeEDNaaLn2UiQybRLlyunCBgYu?= 
=?Us-ascii?Q?  wxDgTqE  PFmZ  6R j SESEfnKOmmOJ3CmfrGpdscVRA7GzoZDWYRID;hgEycxlObB?“ 
=?us-ascii?Q?20SrmGlSNQyWQbRXmuLJAAu9DlJTieldSmeG4NJ6zmykilSpsUi5Aldxm3xP?= 
=?US-ascii?Q?YOHfA5Rk6q9+4V/4XlY64zNaVhlOMJMa4TtDNUU7icLGU:vhj31vP+f/4uB+d?= 

=  ?us-ascii?Q?7c0vFh7Z/eESf Ds71i8irgvhgGRredGN41VFxOuEem5sX13aDYN3FTvf AEA4  ?= 
=?US-aScii?Q?enhl5qt5uFYEtAl/T67zatpvYlMlrUi.IKlJ8GRKzR7f/ds6mx2bAXhLxJw4el?- 
=?US-ascii?Q?qraJZXLpOpmYhblN|tYOaE+8NhX/KwAtosSS;5l4UXWgKn5m3fXtqndxXSwUpKy?“ 

=  ?us-ascii?Q?WIVblVmOPv7ubMo9UNiXx/ el3PBnPmC4+ j  aLYai j WeEluO JEG0D7VYbmGeM6?= 


=?us-ascii?Q?MSR8yx6VDgzgxbRvbPI6FhyPi08rCQwQDXDdEMf 5ApBiWyS01FgolDXxndBv?= 
=?US-ascii?Q?HQm2/+Zb7L/VtZiJ9b5vCfi2:h/z7SVelYUWvlXukStlkxly&Btndqy5QLLLW?- 
=?US-ascii?Q?ZgSIlitQgF6NiTe95QzuGiogczb666+YXa4SOpfvOzhCcJxSMUq+MUAUCwnSPlN 
=?us-ascii?Q?LRUg8iUK6CqnJ2XplILi9cZW7vn+GsRcTcMUnEKru4k6qxlGT61eqk40rdB3?= 
=?us-ascii?Q?eCUsY9N0NBaJgjnj  sYj6?^;* 

X-MS-Exchange-Transport-CrossTenantHeadersStamped:  BYAPR09MB3237 
X-CrganizationHeacers Preserved  3YAPR09MB3237  .  r.amprdO 9  .prod. outlook  .  com 
X-CrossPremisesHeadersFiltered:  CCCASV02 . CCOUNTY . com 
X-CrossPremisesHeadersFilteredBySendConnector :  CCCASV01 . CCOUNTY . com 
X-Orgar,izat  ion  Headers  Preserved :  CCCASV01  .CCOUNTY.com 

X-MS-Exchange-Transport-CrossTenantHeadersStripped:  DM2GCC01FT006 . eop- 
gccO 1 . prod . protection . but look , com 

X-Forefront-Antispam-Report-Unt rusted:  CIP : 162 . 217 . 184 . 7 9; CTRY : US; LANG : en; SCL : - 
1;  SRV: ; lpS:CAL;  SFV :  SKN ;  H :  CCCASV01 .  CCOUNTY .  com;  PTK:  Inf  oDomainNonexi stent;  CAT: NONE;  SFTY :  ; 
SFS :  (19627405001)  (8676002)  (2940100002)  (1096003)  (5660300002)  (55016002)  (109986005)  (893600 
2)  (86362001)  (34756004)  (83380400001)  (9686003)  (7416002)  (450100002)  (28085005)  (52536014)  (45 
080400002)  (186003)  (336012)  (166002)  (83080400001)  (82310400002)  (81166007)  (33656002)  (26005) 
(7696005)  (21480400003)  (6506007);DIR:INB;SFP:; 

X-MS-Of f ice365-Fi Irering-Correl ati.on-Id-Prvs :  b2alb3c9-afal-464b-f 65e-08d81cf 6a335 
X-Microsof t^Antispamr-Stotrusted::  BOfc  0; 

X-Microsoft-Antispam-Message-Info-Original :  =  ?us- 

ascii  ?Q?vacDUPMr.BNFqk  j  DGpl  XhwU01K8/,6qtPwuCMY81  Jb'jnFBrhMvok2FcDr.Gj  wvE?= 
=?us-ascii?Q?lG3mABVb3kAutKMio6t3Su61vFUJN7QR9+UN8Mf 8CD7+t+amh2laulHXdtMT?= 
=?US-ascii?Q?m9wvRVeUoKQSrG6AgHzSZYAM+IvrljQYxbtRQi3UMLRx81TTFk/icWpNhEQzf- 
=  ?us-ascii?Q?f ASB9f ilRzz JWEN8oeGE0bMO2PkokfBCiuGj  qj  5YIRb7MCLV2  60Zldj  r3Dnu?= 

=  ?us-ascii?Q?smLj  QK8p2Q98f 86S8o8f 6qICPhNGakVgTP0Q0VsvazQ/ oRYWHRxavvVF4pR?= 
=?us-ascii?Q?zl8A7TQQ/kdBZklPIO+eRbK4SlzmlVCahjLxPd5U7K12eyMUYIula/yvNDG8S?= 
=?us-ascii?Q?hPNmuwQ6MD8o4FxwcXmM0gzyjbE0doEWedeoa7gKfcbpgceC3ikcb8Ak5PCv?= 
=?us-ascii?Q?CtDqVHpCTko4fvxQOGHXol2qFM6x3mf 6MpEp@6ey3:CzorIsZ JJQ9LmW5VBQV?= 

=  ?us-ascii?Q?wzTMUWpWdNAMepU9IExlixad97ah2  +  fEaPOZxddzE6sTqBsf yvVILV6 JuqC2  ?= 

= ?  u  s  -  a  s  ci  i  ?  Q  ?  f  5  f  ac  z  j  c  i  I TOgKHkz  L7 1 YkFlESUfirBUu  kKpKH j iB+Xu4y6Zacxk7F2:ItBSnC?= 
=?us-ascii?Q?W2dfzeFINMvxXMlZajG+o/IgiL4TWoJnMg7 f  k  3  /  5  i  r  s  7  z  Y  D  g  s  U  u  2  k  1 5  z.  f  d  3  f  k  ?  • 
=?us-ascii?Q?IyWAMOC+mqYNA132MOTCdPizuBOCeOvGcmYNf +90oAVMXuuboDeaSf zUMFaf ?= 
=?US-ascii?Q?S4om39vx91rbN.xhvX0E6q3bEYr31O+QE3hYzbchG6HkAyVmtlIYOHaPBhToBf'^ 

=  ?us-ascii?Q?evfO305CBo j  elR5bGgZH7azYNtf 4q3hh7Rncv+mXlWe J7uf a351p40j  FQZe6?= 
=?US-ascii?Q?lFJOSwvQgcnCbh7yOsC7Y9aXViz9w6A/aMz/qIiTli75djPUGvKR5SpN3deR7  j  ?= 
=?US-ascii?Q?kvGdIqtglIICGYJ2XgflgC.ZeiiBel9f6jWAOF39zNlMDtjttmm9Wzl862A2:haa?= 
=?us-ascii?Q?Vw2t91pIIKeGelsNDazwIKOQtndZVKRj fqUg2y/NALj J18M8mDa01b9dBmfY?= 
=?us-ascii?Q?  1  YDhb  8  7  y  qbb  VG1 8RQNN  zR  J  621 TKM9  zPveIv6aB9  Qm7  P  3  Xn  Y /U  j  j  B  v  4  f  QN  j:lg  f  ^ 
=?us-ascii?Q?LtuzdclWEqaxpvV2vQJts5wqyv8URekMYFNm+FGdM+DGrz8EXvVZxfVxeeBy?= 
=?us-ascii?Q?pWj  rvBTtWTTsB0QLsa/SqD98Cqw  I  i  aREBK/qxl  k  JX4  DXcuyPBC  I  c  +  OEpNCkh?--: 
=?us-ascii?Q?DdiA8/vB0Ub0DOduO6283cLip62fsbaXDwMn7A=3D=3D?= 
X-MS-Exchange-Transport-CrossTenantHeadersStamped:  BYAPR09MB3126 
X-OrganizatibSleaders Preserved:"  #YAPR09MB3126 . namprdO 9 .prod. outlook . com 
X-CrossPremisesHeadersFiltered:  CCCASV02 . CCOUNTY . com 

X-Cross  Premise  s  Headers  Filtered  BySer.cConr.ecror ;  CCCASV01 .  CCOUNTY .  com 
X-OrganizationHeadersPreserved:  CCCASV01 . CCOUNTY . com 

X-MS-Exchange-Transport-’CrossTenantHeadersStripped:  DM2GCC01FT005 . eop- 
gccOl .prod. protection . outlook.com 

X-Forefront-Antispam-Report-Untrusted:  CIP : 162 . 217 . 184 . 7 9; CTRY : US; LANG : en; SCL : - 
1 ;  SRV : ; iPS : CAL ; SFV : SKN ; H : CCCASV0 1 . CCOUNTY . com; BTR : Jnf oDomainNonexi s  tent ; CAT : NONE ; SFTY : ; 
SFS:  (186003)  (26005)  (6506007)  (28085005)  (34756004)  (7696005)  (336012)  (7416002)  (2940100002)  ( 
21480400003)  (8676002)  (8936002)  (1096003)  (45080400002)  (82310400002)  (5660300002)  (166002)  (8 
6362001)  (19627405001)  (83380400001)  (55016002)  (33656002)  (450100002)  (9686003)  (52536014)  (10 
9986005)  (81166007)  (830804  00001);DIR:INB;SFP:; 

X-MS-OfficeSeS-Filteting-Correlation-Id-PtSs:  0472dl90-725c-4fa2-7033-08d81cf 6a757 

X-Microsof t-Antispam-Untrusted :  BCL : 0 ; 

X-Mierosof trfAntispam-Message-Info-Original :  =?us- 

ascii?Q?H7j  3d3akoUwDyOX2s6yWLOxFnSAYOKF32  90WQHrl3p/ d8mEYG8zvO/kiQM8V?= 
=?us-ascii?Q?MkinVrHYN6IzhfgJK8NzVkcDiZGhdwwmbIQhifU7 J6RUwpW01pPxGgPKR6vm?= 

•  Pus-ascii  ?Q?mlbrYHQbV7 L/cRl  ggcEkG-l  DoQTFT JSiur,W7OqK0QxK8Fi:FdzqTQuFKUdW8CB? 
=?us-ascii?Q?6AmBjbOIiw8DWDnh5+MD96E+GaIeID2ZScqHY7WR8Fwc8dwnqK+AR2mhcKSC?= 
=?us-ascii?Q?c7  8Qs9VfCX3ze431MdCtE7 /XSwJLM7mgUvxOv/PaOPKUXmOEb01i7YTOCybnNfi— 
=?us-ascii?Q?R524x62b6a+eWznIZCc890xsvYFb/kAVF3oLDaN59omqYOZTzf snJQF+bR2V?= 
=?us-ascii?Q?FNdn3 j  c9wz4E6DFrWg/VyWm60ikSkZYid9mbDSPNm3KddRq4seey7DlCJ+f 9?= 
=?us-ascii?Q?hJT/zIE;ZfccUP9WlDiXFVocLUFb.L/EKF!GtCq/0S6j£feIdoJLnThSeta6DSmAW?= 

=  7us-ascii?Q?beAVv3PuJs7Ll/RfqPhNMj  c2ZNp3qluhf luVHPec5cmvwN3NfGn6cueg9e9h?= 


=?us-ascii?Q?UGcwxLdB3QJBRyx7PCjdb29FCkbvKrdJrylx5sHimnfyHVAnhQyNeSsL21Gfy?= 
=?us-ascii?Q?t4ttI  J9wuwf  fHuhlpkMpdnKj  /Bz3EiGTmNrNsSDkmT QJ9Si  Mai  I  j  txdKIyqd?— 
=?us-ascii?Q?/70j::2rJNVi02io4pWwQKEVbRH+OSl6hjuMo2irpTQejsc8oZfpSIWM+OvEfZ7- 
=  ?us-ascii?Q?mxRhlNl/ZNh8EEeO j W9561tNkn9RbI3Bb6drGAdNo/ C+Ohj  G66wgKyqtew2N?= 
=?us-asciI?Q?KXt®Urm5wIglIBHHxxhgJ4Qkq/u4nohfXTvd9gtMXHw05etyzlyJW6DnYAuQfN- 
=?us-ascii?Q?DHG7+d5grPzZ8XhKkY2CAb3fmzUSo4IWMqILtWaPTdXbw/nLC4YswidYGm8y?= 

■  -?us -ascii  ?Q?uyaF3  1F2  I xbWPDi B3TQ7.Uxzm4 f  j aslur,50haCf ZKq/DSWDZprnVRgq t  wUKxBV?- 
=  ?us-ascii?Q?E5oOGJ7akf jRcwMUtAiRILJvMG/ uICFrdlkj  2CS9qY03Ie9g7oyRlZqS2nMh?= 
=?us-ascii?Q?nKrXt4PRR4V98IKrGrmMBQxGfCxsy0LKt6Se0mWo8 JbTReA=3D?= 

X-MS-Exchange-Transport-CrossTenantHeaders Stamped;  BY5PR09MB5969 
X-Organi z at ionHeaders Preserved:  BY5PR09MB5969 . namprd09.prod.outlook.com 
X-CrossPremisesHeadersFiltered:  CCCASV02.CCOUNXY.com 
X-CrossPremisesHeadersFilteredBySendConnector :  CCCASV01 . CCOUNTY . com 
X-Crgani zar IonHeaders  Preserved :  CCCASVOl .  CCQUNTY. com 

X-MS-Exchange-Transport-CrossTenantHeadersStripped:  DM2GCC01FT007 . eop- 
gccOl .prod. protect ion . outlook.com 

X-Foref ront-Antispam-Report“Ufttrusted:  Cl? : 1 62  ^  21  7 . 184 . 7  9; CTRY : US ;  LANG : en ; SCL : - 
1 ; SRV : ; I P V : CAL ; SFV : SKN; H : CCCASVO 1 . CCOUNTY . com; PTR : Inf oDomainNonexi stent ; CAT : NONE ; SFTY : ; 
SFS:  (7696005)  (81166007)  (7416002)  (9686003)  (83080400001)  (450100002)  (21480400003)  (83380400 
001)  (52536014)  (8936002)  (19627405001)  (1096003)  (8676002)  (55016002)  (34756004)  (186003)  (2940 
100002)  (86362001)  (28085005)  (26005)  (6506007)  (45080400002)  (5660300002)  (33656002)  (10998600 
5)  (166002)  (82310400002)  (336012 ); DIR; INB; SFP : ; 

X-MS-Off ice3 65-Filter ing-Correlation-Id-Prvs :  6656c69f-ce4e-458b-a825-08d81cf 6aed5 
X-Mi crcscf r-Anti spam-Untrusted :  3CL : 0; 

X-Microsoft-Antispam-Message-Info-Original :  =  ?us- 

ascii?Q?KyeCcyPsiXf JHcTkhqbntrzp70Z/K5AvKppenGFhy/9FEYnV8ZEv7QxnXZY6?= 
=?us-ascii?Q?bOzW7Axfi6cS81zUdfTCXjCS9C3SHaYipA5x8+4+HD8rXGFjB3Mj FtJxUTai?- 
=?us-ascii?Q?RVNM0/UxZ0Q0cfQ5U0f +03H8MpL+9VmiZrRYD0Zu5ZptAKycGwVSbgInn5Nz?= 
=?us-ascii?Q?NoQMrqMZ  JPNp82clmc9a0Q0  j  j  FvR/ucEbri/EUCdE6VXsFOtYgbc5eBYcBaz.f  ?4 
=  ?us-ascii?Q?6waq31xWZ j  OPSYmMEZHn2QjB9iK7q6fCPUlWvf 99s31F5PvZh8s JzDg6rq5t?= 
=?US-ascii?Q?4ML/CuHv383cYLnNVrmFAfGd6Q5NxDKwnkM551ZFYeD4++UQ4mMACB03UK5+?= 
=?us-ascii?Q?lt9vT82TG3mrv7ATbE+4hu/fLc5+bm7LaC7yDr3MkB89hkXpvEGCn4Hsptxrt;f=? 
=?us-ascii?Q?Fv5ClgYAty2+sHkEiUvqFJBNefpZid5CHYOXmIgskl JKnkIvIVRteZiR93n6?= 
=?US-ascii?Q?mp5sA4fX9rL0Xf+z8cS3VkgrNggsBKcKf 4  9SMVt jgI7XZ/7uVgswLkfuxEWllN 
=?us-ascii?Q?elud5icFf 5gFdj FYbViFK/ C55kXuKnSUYtCxYXTsCGIAhBmIhRaKfdlnNI5d?= 
=?us-ascii?Q?YxwwJyCqQ7 /V3KKkoFy?EYrMAwUm9bQJSSrM3Iy/wU5 j kwUsR9 j  ZCPibhUdi?-- 

■  7us-asci  i  PQTpDhbszCcvf-'VCVJSpqXliZOlOf yqcl  /  VI MNs5G65xAngRS96vuBpRYSokcRAkQ? 
=?us-ascii?Q?pSBqQC8pw9W7MYneCf Zwu4PN2wkVkFj IQdkd04PCEpu4rzoHL9uZsBrUPoI J?= 
=?us-ascii?Q?WLkJU4 JsF6Kz6PGSSBH8Zqn5 JlgK7qt63C00Utt!XpVeXQ39ZO4WcUTs3hS3B6?= 

=  ?us-ascii?Q?xwo5nJHuZGhllU9CseKph5Gmfq9v41WTrsuRj05GwSmJdMj  f / j BiemHlZpgN?= 
=?us-ascii?Q?tI2>27AsieNDUxsgI+RHaeZEsLOcsm7  95/TEwRQj  ca9DtK3q61npYpx2s4YDd?= 

=  ?us-ascii?Q?RnNjm5vboOcWC8F9U8WfLNj  6 j AcGkosyDuUJK4 JCCVINXKK9C521sqr8NQT0?= 

=  ?us-ascii?Q?si JgbDNwf 55S j Vr2  6Q9nWI/XC/ ohGQirn9UDEQZh+G/ GL70DnDAqteQnQMj  o?= 
=?US-ascii?Q?vK7QIocozmaQDesTjSZPRj  ebQ2GJA6EY10MXq+D+cb8e7zJvvaEpfs6tGmPy'?;- 
=?us-ascii?Q?RfnT6GWRM4SbA7wunxafHcJMDPvOoFajOFcwsOK8KL511olOc+3fMTOChcSx?= 
=?tis-ascii?Q?UoC3NvS5/viOBsQ4dkOlvlqg8L>2DMJxPY841lk0=s3©“3DP= 

X-MS-Exchange-Transport-CrossTenantHeadersStamped:  MW2PR0901MB3819 
X-Organi zatioHMeaders Preserved:  MW2PR0901MB3819 . namprd09 .prodi outlook . com 
X-CrossPremisesHeadersFiltered:  CCCASV02 .CCOUNTY.com 
X-CrossPremisesHeadersFilteredBySendConnector :  CCCASVOl . CCOUNTY . com 
X-OrganizationiJeadersPreserved:  CCCASVOl .CCOUNTY . com 

X-MS-Exchange-Transport-CrossTenantHeadersStripped:  DM2GCC01FT007 . eop- 
gccOl . prod . protection . out! ook . com 

X-Foref  rent -Anti  spam- Report  ^UitttEus  ted:  CIP:  162 .217.184. 79;  CfRY  :US;  LANG:  en;  SCL 
1 ; SRV : ; I P V : CAL ; SFV : SKN; H : CCCASVO 1 . CCOUNTY . com; PTR : Inf oDomainNonexi stent ; CAT : NONE ; SFTY : ; 
SFS:  (7416002)  (45080400002)  (450100002)  (83380400001)  (8676002)  (336012)  (33656002)  (7696005)  ( 
83080400001)  (166002)  (82310400002)  (109986005)  (81166007)  (9686003)  (52536014)  (55016002)  (260 
05)  (2940100002)  (8936002)  (1096003)  (186003)  (86362001)  (5660300002)  (21480400003)  (1962740500 
1)  (6506007)  (34756004)  (28085005);DIR:INB;SFP:; 

X-MS-Off ice3 65-Filter ing-Correlation-Id-Prvs :  fb4d3d08-2852-4452-d783-08d81cf 6blef 
X-Mierosof t-^ntispam^Untrusted:  BCU : 0; 

X-Microsoft-Antispam-Message-Info-Original :  =?us- 

asCii?Q?mOheSDvPywlVKe3YLS33roidKXU4McbXS8FL6Qc8kyQfNhRJgAmOK718hYu/?= 
=?us-ascii?Q?hNdGPUecQcwBA7Ww/ fChXRbOvXaPnzcf /ThhbuFgkOkZdodcf oE J9DMt80wN?= 

?us-ascii  ?Q?xI,z  I  cDRSu6Ze09EdAA3k9ZXLM5YHCAA6pI  j.MB27GWJKbOAOkVs7S565/qCvw? 
=?us-ascii?Q?legutgZ,tf  Yj  deUQIolCzdklixXZWQDY3sVCAmccMiS4n+WVVpfwdBAtc+KNvy?= 
=?us-ascii?Q?+uOWrQeLkJtkxxY68xQL8nf rlZolPDR+f ibKwtnVn5eN6olZ2/H5hwNSaIrK?= 


=?us-ascii?Q?BEIkcLggAervPWojykZ10NH5GlpfXb0nzNhIMyNI/m07NEZ6o24eUa2qB10A?= 
=?US-ascii?Q?OTqXOYP2WAYCOkM4XztG5r5£FERh7eXmgOAjNwj  ihmagGYUzQJtRs/STJtgdU?- 
=?us-asGii?Q?UcnckhlE;VevBe/y7I/a7y/LlYM/tB29sE8u/qRHB/gmKlWDpiuWiOrPdY4CnR?=! 
=?us-ascii?Q?CVtZG13pX3Eyi+S/4rVK+cX6t2YLPvkPVI/XNGHzIXruNXcAH+/0Q8YGQNe?= 
=?us-asciI?Q?GfLYJIf  Fe9dm2  6fB2T8CPIFhmS8Ckdl7f  kkfgOsvmVhVEJqovtSfrlOu&krQIlf— 
=?us-ascii?Q?iF4AmyBNugErBY6d3QyhoU/i8Me JLwAzTU7DsbI JW6zsGkhHRwwP9V/W2bUh?= 
~?us-ascii?Q?RigikTSsXx43Y,zta22upTKQSqvzlFtrmGlYtQyF/bwjWesFHo6zXXLuiGEMe?~ 

=  ?us-ascii?Q?TSLPUjUS4  6C818XWxRFw3enyLIkm8s/gq8zluU16Hs j  QGcSbgH6ZQSdwEsZh?= 
=?us-ascii?Q?/MR4aUWH8JlkLgUBri01AlnYePKSMc45Mg4gfWldqMRHM+KoUVK/ElPPIzLG?= 
=?us-ascii?Q?cKaFJ14jyIp9/7rokxKkCkK9+yQxdb4AGJNYkRNgAW+045o2TW7hnKTNVyTx?= 

=  ?us-ascii?Q?5L0T2II2Jj  GS9KPDpvInroumj phtKVyZx91GiMh9y32gq4Hbf scFLY/ zMuqa?= 
=?us-aaGii?Q?6kNyHXgIkrYrOXcxqpKXKI?WRfsB23BZ<JFlLqLWSWlLlhbVC)vI,q3;R+CU17nJ?- 
=  ?us-ascii?Q?IaONSBr+SnQXcmNxkDyCq7DmGGLisdx6bTmUUl j  9rcgZPY00nF4my0 JH1FRU?= 
=?us-ascii?Q?w6Pri8dliFfqfoWsKiCAEQbpTayHy2h9wTpfV2c2Q/+UIkU8SC41/VKdLv?Zk?= 
=?us-asCii?Q?APuVWk/FeVF2bIcGlcWCUIv7Qkl44L7F5VkNON4XMxPPUyGvc jqTr2sklh.vC?= 
=?us-ascii?Q?GrFn4D83TlrXGVWWPWdqBJ34rdfQd0UbPL63wg=3D=3D?= 
X-MS-Exchange-Transport-CrossTenantHeaders Stamped:  M\'2PR09MB551  5 
X-Organi z at ionHeaders Preserved:  MN2PR09MB5515 . namprd09.prod.outlook.com 
X-CrossPremisesHeadersFiltered:  CCCASV02 .CCOOTTY.com 
X-Cros  s  Premises  Header  sFi.l  re  red  BySendConnecrcr :  CCCASV02  .  CCOUNTY  .  com 
X-OrganizationHeadersPreserved :  CCCASV02 . CCOUNTY . com 

X-MS-Bxcnange-Transporr-CrossTer.ant  Headers  St. ri  pped :  DM2GCC01FT008  .  eop- 
gccOl .prod. protection . outlook.com 

X-Foref ront-Antispam-Report— SfifcKusted:  CIP: 162 ,217 .184.7  9;  CTRY :0S;  LANG: en;  SCL 
1 ; SRV : ; IPV: CAL; SFV: SKN; H : CCCASV02 . CCOUNTY . com; PTR: Inf oDomainNonexistent; CAT : NONE; SFTY : ; 
SFS :  (34756004)  (26005)  (1096003)  (8936002)  (6506007)  (52536014)  (82310400002)  (83080400001)  (10 
9986005)  (28085005)  (33656002)  (356005)  (81166007)  (7696005)  (2940100002)  (86362001)  (833804000 
01)  (186003)  (336012)  (45080400002)  (8676002)  (7416002)  (9686003)  (166002)  (450100002)  (21480400 
003)  (55016002)  (19627405001)  (5660300002) ; DTR: I KB; SEP : ; 

X-MS-Off ice3 65-Filter ing-Correlation-Id-Prvs :  b3501f 52-03e7-4f 41-f 8bd-08d81cf 6db63 
X-Microsofr-Anrispam-Unt rusted :  3CL : 0; 

X-Mi.crosof  t-Anri  spam-Mess  age- Inf  o-Orig.i  nal  :  =?us- 

ascii?Q?biBnQqT5RkEMxAEqhD7Z4Dwh9el J5GmrqlWPWdqL61ZhgzqaWFkhbRWiUGar?= 
=?US-ascii?Q?Xjhf9io/Ao+RBS8WMNsBXyG4xSi5nNI14Jd4V2G9mz4mz6fw6kIFDOXjBl+B?= 

=  ?us-ascii?Q?BkZH19KATZai j  4gf 4RH7xhf 7  3YGExxwHU7Cl/ Sap4oMAenLcb6gAGuNxGXEV?= 
=?US-ascii?Q?KXGmBB+hlU6V0rSbPOZvO5W3qgEnzJ/M0lgSJ+Ht29B2VMviSRmutqDlWhqb?- 
=?US-ascii?Q?S984njF8heEfVI0Ij5pjrHzcciO6ZNlXNgfhqQ0RQM/YuG9FlxJ/lpfbRCXT?- 
=?us-ascii?Q?QidEbXs08xfldaza4KnCLszucfXNP7Z/lMLjs8Wqqq6q7CpGvK8jyPxOF9zO?= 
=?us-ascii?Q?5.f  j  DXF9JP/DhWlAJGV+QPY.cWa3NZRcRdYypymFh+nHN4EbyabLZJlcuCu2yy?= 
=?us-ascii?Q?ouc59JgZGrfmbaxf2 jRcOeTg55BRWaOo7+/AGxlRFvMrlgcdsOn71sCo9SGE?= 
=?us-ascii?Q?AsPwV'HGhNgrJwU®3i6n0XtcnZerBW9G0t0P:2szetyzYh8UcX3LUSlflTiC/MR?= 

=  ?us-ascii?Q?RlKULSse4Md4qZVwS4aksU6qc+T81VXcoxUb09Mj  8pekNC+AMwDqFh8ZGC0Y?= 
=?us-ascii?Q?vBqeztyWirBubASKhOFmuX8N55208Yv/K+WB7A19f0rtGQbLPd3SGSCVcVEI?= 
=?US-ascii?Q?FWyePnbmIY2dTg5wqIty6kPdLWuJej ASOpPmP5DYqUBQBL5u+Mcx9qAMmhHfR— 
=?us-ascii?Q?UhsM/uvnxsuMhgy9ZabSAnfwFLH9LmUy6aHL2lbH35kveZIInoKxyoMV604G?= 
=?US-ascii?Q?H8A7eZcaGDxRWkePHVfZWux8COGIl+ZC27wZWNj zVO.nul awHmRcp9r I Cnf CY?  • 

=  ?us-ascii?Q?EgaPYG3qvdO+zAtxFJWOA5hi3wgpj WtmwP/4nz jbPCj  j Voo/BL7aWdyRTr7t?= 
=?us-ascii?Q?uwApHkiMVcyvf +wYcJOCHftIg3SFhdhFLmKxH+69fxyAcpxOZqv'znSBa+ j  +1X?= 
=?us-ascii?Q?lGYo4NhBeE91iL5;RdUj  69FNqrqWr9abOWXBDG;j  SwNqsubn0g/tFBAq6GTedv0?= 
=?us-ascii?Q?0Sa3Nr2evFFbRtvxZ+VPZ7qt+tPlCQ2HVkEMpyw3Vf DpYiPfLQCSrIP/TKkY?= 
=?US-ascii?Q?4K8SR3!KTDfMphyppyzg/lRd9QDOHV+bB8AJQqcdXEkaZzKgpIyc8p5PSx.Sd3'?:=! 

=  ?us-ascii?Q?C5bj  7  06f ZuaGJ7YultnKTz  +  0qcDVzxqgAUX7  7AQtxkg+14TlvO3oIUPi5QxF?= 
=?US-asdii?Q? JkysUAa3grXIf Q7oY7R2-5orEf Gj  5Xt6XUS07wjobNJmrVj  xWirLDmWS09Ps3f— 
=?us-asdii?Q?7IPMiCen34st  wmDb ' 
X-MS-Exchange-Transport-CrossTenantHeadersStamped:  SA9PR09MB4638 
X-Orgar.izar. ionHeaders  Preserved :  SA9PR09MB4  638  .  namprdO  9  .prod,  outlook,  com 
X-CrossPremisesHeadersFiltered:  CCCASV02 . CCOUNTY . com 
X-CrossPremi sesHeadersFi.l teredBySendCcnnecrcr :  CCCASV02 . CCOUNTY. com 
X-OrganizationHeadersPreserved:  CCCASV02 . CCOUNTY . com 

X-MS-Exchange-Transport-CrossTenantHeadersStripped:  DM2GCC01FT005 . eop- 
gccOl  .prod. protection, ..outlook,  com 

X-Forefront-Antispam-Report-Untrusted:  CIP : 162 . 217 . 184 . 7 9; CTRY : US; LANG : en; SCL : - 
1 ; SRV: ; IPV: CAL; SFV: SKN; H : CCCASV02 . CCOUNTY . com; PTR: Inf oDomainNonexistent; CAT: NONE; SFTY : ; 
SFS:  (26005)  (33656002)  (450100002)  (28085005)  (34756004)  (109986005)  (7696005)  (19627405001)  (9 
686003)  (55016002)  (45080400002)  (5660300QQ2)  (8676002)  (6506007)  (166002)  (7416002)  (214804000 
03)  (52536014)  (2940100002)  (186003)  (356005)  (83080400001)  (83380400001)  (86362001)  (8936002)  ( 
1096003)  (336012)  (82310400002)  (81166007 ); DIR: INB; SFP : ; 


X-MS-Off ice3 65-Filter ing-Correlation-Id-Prvs :  a58626f 3-998b-4afa-b83d-08d81cf 8f 857 
X-Microsof  t-AntispamM3ptrustedj  3 CL :  0; 

X-Microsof  t-Ant.i.spam-Mes  sage- Info-Original  :  =?us- 

ascii?Q?wpX/ nsKEukMXOpuqLquwXj  j  THKKptLX2VGOCK3yMIhAu/lIK17  6uFAru8mlR?= 
=?us-ascii?Q?9tftU6Xzha+zF+YVtaX5AbfIb9NABFLT8WDyB+Owz3t8usEN+h/yhYpDD8ysv|= 
=?us-ascii?Q?t6Xdz0kyKf f sX9qMcKxYOkpIeIVqR95w72bfGCcbCULcKDPsXbAI068zLHrp?= 
=?us-ascii?Q?BWsM4AbNBXj,,SOIOanl4rPfaNlMaOmZQxxt2DWXJb2Pp:rVg6AtbB4nsJJDda?- 
=?us-ascii?Q?OrusgELKg9w3/yCtLQCRHEz3GSBTl/7pNVRxXzpJBA6FkWGXDui8PlTM9BfM?= 

=  ?us-ascii?Q?eBKDiINw+xBnbNMKpIcN9g8aSCmr4htf I4i/lUlPZNE8bWseEhS90K7Gh7b2  ?= 
=?us-ascii?Q?By+yaa5NFiflAQbEnP3+t3uqty3jRrfi/lkKkrBg2FxWkkTCkIIgCtyz/yuCt4?= 
=?us-ascii?Q?MP70pH3wIXylNsbB0EUzgp2PP5RbdfqQvd25FlAk/fIh8BXt5bCwgd+Axl/U?= 
=?US-ascii?Q?x+CjSJSTZPWjYVvQvyHt7Utk20d8T4ONiI0+hxXY45Wupyo63RiRLp9GWY7?= 
=?us-ascii?Q? J8 JS6onsSmYysl JGcbWOvf ylYT+sXzsPHME+QiHqiGVBIc3ywSZGDirsikaE?= 
=?us-ascii?Q?mzBfiYtlyxCcRAaZlOsgKOYPteEj.efTi0FV6FX+oz4Xh2tOlvq+fxrKYA9NXeC?= 
=?tis-ascii?Q?lYcTes+X0Gz3VB9O/lUHiti/gxSCJiKdj;qEr/57bobFC+Zh7OE0sr3aBYllWLw;f= 

=  ?us-ascii?Q?f f lmcdiPpZlTWs4KZA9NJ6 j ASCHVY05sI Jgj  7Gj  FaZ6hMAwy7 IX5CDZOJISb?= 
=?US-ascii?Q?TyQrc5CFC30dsfvXRN/Jv8fKE4bpilyi6z46MObCbGdoj8d+Nnyk7V02qWNH7?= 
=?us-ascii?Q?lzpAXHT19sHMJlbBn7DcH0s5fhjSpYqN0bIP4dG/TlY2+VloXp/0b0sqeVnR?= 
=?us-ascii?Q?k3oIRMyf 9h4vg2ddELf iiOyZgW91st0tXPqyerdGlG6OLdPFxQc+Vv3S9bd4.?= 
=?us-ascii?Q?f PqoLvVMYdf PVMDc3+bl87MS3lZgOdJqRzGkjphxsMFLLDPrutep4pEdXeOp'?= 

=  ?us-ascii?Q? j  nwf JWlxZllDEi/l+MOEwelwU67SZ j lUx0rsou2SdoAAlf tgVrhj  u2MuPL+x?= 

■  :?'js -asci  i  ?Q?hpcOm1  Kwv87ajT9WA1  gpOq2SP9KM0bZI.e0HHyWcO027  6vZQLsI)Kb6du/WM'r.  P? 
=?us-ascii?Q?7qFcSxwUkAfkMc5INYtxSFVlBZHTBb60SNrw2PCbBQOw51RlqIQ8yxfISl+a?= 
=?us-ascii?Q?vrk52/FHpERb3/eW59/  zRpdWMCwYVI2z+Vz5+w=3D=3B'??<“, 
X-MS-Exchange-Transport-CrossTenantHeadersStamped:  CH2PR09MB4588 
X-Organi z at ionHeaders Preserved:  CH2PR09MB4588 . namprd09.prod.outlook.com 
X-CrossPremisesHeadersFiltered:  CCCASV02 .CCOUNTY.com 
X-CrossPremisesHeadersFilteredBySendConnector :  CCCASV01 . CCOUNTY . com 
X-OrganizatioiiHeadersPreserved:  CCCASV01 .CCOUNTY.com 

X-MS-Exchange-Transport-CrossTenantHeadersStripped:  CY1GCC01FT010 . eop- 
gccOl .prod. protection, outlook, com 

X-Foref  ront-Antispam- Report :  Cl#  i  1 62 *21 7.184.79;  CTKY..  US’|- LANG :  en ;  SCL :  - 

1 ; SRV : ; IPV: CAL; SFV: SKN; H : CCCASV01 . CCOUNTY . com; PTR: Inf oDomainNonexistent; CAT : NONE; SFTY : ; 
SFS :  (8936002)  (1096003)  (2940100002)  (86362001)  (186003)  (26005)  (34756004)  (28085005)  (1962740 
5001)  (6506007)  (5660300002)  (21480400003)  (83380400001)  (336012)  (8676002)  (450100002)  (741600 
2)  (45080400002)  (82310400002)  (109986005)  (52536014)  (55016002)  (33656002)  (9686003)  (81166007 
)  (7696005)  (83080400001)  (1  66002) ; DIR: 1K3; SFP : ; 

X-MS-Off ice3 65-Filter ing-Correlation-Id-Prvs :  6f 58c0f f-fc9f-4f 7f-2bd4-08d81cfbl72e 
X-Mi crosof t-Antispam:  BCL : 0; 

X-Microsoft-Antispam-Message-Info :  =?Windows- 

1252  ?Q? JAU9k41FY5x9/Fy+KKg8Xj;Q2wL3CvH2UyAQ+veIk8xb7Ey3xTXDxiDtI?= 
=?Windows-1252?Q?M4UwLXU8/tPhV30q5aYmyElNumSW5VjGMVUAq/PXopVwCTiFMfHGJnMW?= 

=  ?Windows-12  52  ?Q?Gq8Xt2c7TcL16HIMDOslMgdTr7  5xaGYBww7UrheHhV7EnIUz3ImwDq4 J?= 
?Wir,dows-1252?Q?kyt/a3y0Mvp573uwnaV  I  i  CrM'J  JVEu  I  b'J  I  p6v4  55e3sKj  IdkZrIafFXCO?= 

=  ?Windows-12  52  ?Q?XXmqLxIRjhZtEbsdbWrgl4  62bvX64p7Q2EHFBVHd0HckJzQP/ CT2 j AJ5?= 
=?Windows-1252?Q?3wM8/H9+VRXwu7W21VaKKmiXGHydUP4Llxlml+9Kooq8FzrZ3+vKg/Btr?“ 

=  ?Windows-12  52  ?Q?kK/OUiuFlL4dCQDmBE j lXkvDBlt/ d5LJctIqvi01LS JlLTRw7tmxAcvb?= 
=?Windows-125a?Q?9xA6tYw710KKRTaPH+UbGGLNHY5uZ7ACndzve9lZHCyftlyNeldkP207?= 
=?Windows-12&2?Q?lQ6tB8Bf8IAAJcHfSde6eJVNj8fs+cJkL5v3lAjCYvlqMObh5M8vnWVU?= 
=?Windows-1252?Q?9R/RELmO+gblSLwq4UDYnwF7krT5iM914xh9k6yXe6/rFVODODnfNnPP?= 

? W indcws - 1 2  52  ?Q  ? JmB l.MJ  Ugu  4  j PXs6aFZHDily9FUnmFelbOn2vSLoOiRrovr4ip3meB92a?= 

=  ?Windows-12  52  ?Q?ZRmF/ qBewNblObf OkYJOZlngAUMDKrOBZ7Hm099LlxyDuren7  zu2Zef D?= 
=?Windows^l252?Q?dALOavGamCnil6U5mNcOXrrvgBcPotCYGsbDHm7TAlvz4YgWBIs jeHHAIf^ 

=  ?Windows^l252?Q?XpxgAbyJQigCMrK6ddboeA8ls+2gz65  7f  7yBllXApb6Nji,iQY70rwqiFf  ?= 
=?Windows-1252?Q?YdNY8LYUi21XUA1455S+/7BEEdTLuPYS0bCm3qwvOp3Ak5nr2ExRaQaj?= 

?Windcws-1  2527Q7K1 1  VwdJ I j  traUj  zngzYQ6JkpGd7QLs7okI)b33R5q/WVGao5dj  5x5Nhy3? 
=?Windows-1252?Q?0q75qsZfd9G6UoT6BKReciMCvMqmeysgxFaWysEdaYQSBTDvpqdwLlq+?= 

=  ?Windows-1252?Q?N623W8ESOAbGQRRivJvVLxD¥tTE1izWGR+o2tg8‘6lTZJd91MaF+NxxPw/:f'= 
=?Windows-1252?Q?TF9E4m/KOJmlV285G5PHqi/qOez8Ax5I8ta6UXwBVyU8v21sG73WnemO?= 

=  ?Windows-1252  ?Q?/ S3LVEHOk4LIvRdlMv9 JAelryzzKFhOYoOrqaKQnRUj  qpa50LMaEUH9M?= 
=?Windows-1252?Q?23iSn6jpk/C7JSVJ+2CU/XzsfShFwgSjiSGBiEjUoImPFSk/3mitAledEs;|* 
=?Windows-1252?Q?5LN4tLt/wX4eSnx+mdhClrWmcDI4zIDFxdFah8PVHfifeEKmVFPk4puo?= 
=?Windows-1252?Q?XSJgo3vrMRySesdgHOM3CLWYMUPvcdvFaXtONQLTkhLmlplx?= 
X-MS-Exchange-CrossTenant-OriginalArrivalTime :  30  Jun  2020  13:40:37.7362 
(UTC) 

X-MS-Exchange-CrossTenant-Network-Message-Id :  4e80628d-db4 6-4cl3-8d96-08d81cfb2c4 9 
X-MS-Exchange-CrossTenant-Id:  8b4d55ae-6db4-4e05-a85c-59d6a256cd6e 


X-MS-Exchange-CrossTenant-OriginalAttributedTenantConnectinglp :  Tenantld=8b4d55ae-6db4- 

4e05~a85c-59d6a256cd6e;Ip= [162 ,217.184.79]  ;  Hel©«  [CCCASV01 .  CCOUNTY  ..com] 

X-MS-Exchange-CtossTenant-Aut'b.Source :  CY1GCC01FT010  .  eop- 

gccOl .prod. protection . outlook.com 

X-MS-Exchange-CrossTenant-AuthAs :  Anonymous 

X-MS-Exchange-CrossTenant-FromEntityHeader :  HybridOnPrem 

X-MS-Exchange-Transport-CrossTenantHeaders Stamped:  MX 2 PP 0 9MB 4 8 4 3 

X-Organi z at ionHeaders Preserved:  MN2PR09MB4843 . namprd09.prod.outlook.com 

X-CrossPremisesHeadersFiltered:  CCCASV02 . CCOUNTY . com 

X-Organi zaui onHeacersPreserved :  CCCASV02 .CCOUNTY.com 

X-CrossPremisesHeadersFilteredByDsnGenerator :  CCCASV02 . CCOUNTY . com 


Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 

From:  CCSO  Intel  (Sheriff)  <CCSO.INTEL@cookcountyil.gov> 

Sent:  June  30,  2020  8:07:45  AM  CDT 

Received:  June  30,  2020  8:40:40  AM  CDT 

Attachments:  (U--FOUO)  MB  -  Criminal  Hackers  Target  US  Law  Enforcement  Data 

06262020.pdf 

Please  see  the  attached  DHS  Intelligence  Brief,  "Criminal  Hackers  Target  US  Law  Enforcement  Data,"  dated  June  29, 
2020.  A  criminal  hacker  group  Distributed  Denial  of  Secrets  (DDS)  on  19  June  2020  conducted  a  hack-and-leak 
operation  targeting  federal,  state,  and  local  law  enforcement  databases,  probably  in  support  of  or  in  response  to 
nationwide  protests  stemming  from  the  death  of  George  Floyd.  DDS  leaked  ten  years  of  data  from  200  police 
departments,  fusion  centers,  and  other  law  enforcement  training  and  support  resources  around  the  globe,  according 
to  initial  media  and  DHS  reporting.  DDS  previously  conducted  hack-and-leak  activity  against  the  Russian 
Government. 

If  you  no  longer  wish  to  be  on  this  distribution  list,  please  send  an  email  to  ccso.intel@cookcountyil.gov  to  discontinue  receiving 
these  emails.  If  you  would  like  any  member  under  your  command  to  receive  these  emails,  please  send  an  email  to 
ccso.intel@cookcormtyil.gov  and  include  their  name,  title  and  email  address  in  the  body  of  the  request. 


Cook  County  Sheriffs  Office 
Strategic  Operations  Center 
3026  S.  California  Avenue 
Building  5,  2nd  Floor 
Chicago,  IL.  60608 
Office:  773-674-2694  or  8477 
Fax:  773-674-4797 


THIS  IS  A  CONFIDENTIAL  LAW  ENFORCEMENT  COMMUNICATION.  The  contents  of  this  e-mail  message  and  any 
attachments  are  intended  solely  for  the  addressee(s)  named  in  this  message.  This  communication  is  intended  to  be  and  to  remain 
confidential.  If  you  are  not  the  intended  recipient  of  this  message,  or  if  this  message  has  been  addressed  to  you  in  error,  please 
immediately  alert  the  sender  by  reply  e-mail  and  then  delete  this  message  and  its  attachments.  Do  not  deliver,  distribute,  transmit 
or  copy  this  message  and/or  any  attachments  and  if  you  are  not  the  intended  recipient,  do  not  disclose  the  contents  or  take  any 
action  relative  to  the  information  contained  in  this  communication  and/or  attachments.  This  e-mail  and  any  attached  documents 
may  contain  For  Official  Use  Only  and/or  Law  Enforcement  Sensitive  material  and  should  not  be  disseminated  outside  of  official 
law  enforcement  channels.  The  information  contained  in  this  message  as  well  as  any  attachments  shall  not  be  released  to  the 
media  or  the  general  public. 


Undeliverable:  Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law 
Enforcement  Data 


From: 

To: 

Sent: 

Received: 

Attachments: 


Microsoft  Outlook 

<MicrosoftExchange329e71ec88ae4615bbc36ab6ce41 109e@cookcountyil.gov> 
CCSO.INTEL@cookcountyil.gov,  Eric.Sellers@cookcountyil.gov 
June  30,  2020  8:56:06  AM  CDT 
June  30,  2020  8:56:10  AM  CDT 

Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement  Data 


Delivery  has  failed  to  these  recipients  or  groups: 

Eric.Sellers@cookcountvil.gov 

A  problem  occurred  during  the  delivery  of  your  message  likely  due  to  a  bad  mail  routing 
configuration  or  mailbox  rule  setting.  If  the  problem  continues,  contact  your  email  admin. 


The  following  organization  rejected  your  message:  CYlGCC01FT003.mail.protection.outlook.com. 


Diagnostic  information  for  administrators: 

Generating  server:  CCCASV01.CCOUNTY.com 

Eric.Sellers@cookcountyil.gov 

CYlGCC01FT003.mail.protection.outlook.com 

Remote  Server  returned  '554  5.4.14  Hop  count  exceeded  -  possible  mail  loop  ATTR1  [CYlGCC01FT003.eop- 
gccO  1 .  prod .  protection  .outlook.com]' 

Original  message  headers: 

Received:  from  CCCASV02.CCOUNTY.com  (10.124.40.40)  by  CCCASV01.CCOUNTY.com 
(10.124.40.39)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 

cipher=TLS_ECDHE_RSA_WITH_AES_12 8_GCM_SHA2 5 6 )  id  15.1.1261.35;  Tue,  30  Jun 
2020  08:40:41  -0500 

Received:  from  GCC02-BL0-obe.outbound.protection.outlook.com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITS_AES_128_GCM_SHA256)  id 
15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:40:41  -0500 

Received:  from  DM6PR09CA0026.namprd09.prod.outlook.com  (2603 : 10b6 : 5 : 160 : : 39) 
by  BYAPR09MB3189.namprd09.prod.outlook.com  (2 603 : 10b6 : a03 : a5 : : 23)  with 
Microsoft  SMTP  Server  (version=TLSl_2 , 

cipher=TLS_ECDHE_RSA_WITH_AES_2 5 6_GCM_SHA3 8 4 )  id  15.20.3131.24;  Tue,  30  Jun 
2020  13:40:39  +0000 

Received:  from  CY1GCC01FT010 . eop-gccOl .prod. protection . outlook.com 
(2a01 : 111 : f400 : 7d02 : :208)  by  DM6PR09CA0026 . outlook. of fice365 . com 
(2603 : 10b6 : 5 : 160 : : 39)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher=TLS_ECDHfii_RSA_WITH_AES_2 5 6_GCM_SHA3 8 4 )  id  15.20.3131.21  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:40:39  +0000 

Authentication-Results:  spf=softfail  (sender  IP  is  162.217.184.79) 
smtp .mailfrom=coOkcountyil . gov;  cookcountyil . gov;  dkim=none  (message  not 
signed)  header . d=none; cookcountyil . gov;  dmarc=fail  action=none 
header . f rom=cookcountyil . gov; 

Received-SPF:  SoftFail  (protection.outlook.com:  domain  of  transitioning 


cookcountyil.gov  discourages  use  of  162.217.184.79  as  permitted  sender) 
Received:  from  CCCASV01.CCOJNTY.com  (162.217.184.79)  by 
CYIGCCOIFTOIO .maiX.:protectidn. outlook. com  (10.97.0.149)  with' Microsoft  SMTP 
Server  (version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 

15.20.3131.20  via  Frontend  Transport?  Tue,  30  Jun  2020  13:40:38  +0000 
Received:  from  CCCASV02.CCOUNTY.com  (10.124.40.40)  by  CCCASV01.CCOUNTY.com 

(10.124.40.39)  with,  Microsoft  SMTP  Server  (versibn=TiiSi_21, 

cipher=TLS_ECDHE_RSA_WITH_AES_12 8_GCM_SHA2 5 6 )  id  15.1.1261.35;  Tue,  30  Jun 
2020  08:25:34  -0500 

Received:  from  GCC02-DM3-obe . outbound. protection. outlook. com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(version- TT.,S1_2  ,  ciphei=TfS_ECDHK_RSA_W  1  Trf_AES_l  2 8_GCM_SHA2  5  6 )  id 
15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:25:34  -0500 
Received:  from  MWHPR09CA0028.namprd09.prod.outlook.com  (2603 : 10b6 : 300 : 6d : : 14 ) 
by  BY5PR09MB3873.namprd09.prod.outlook.com  (2603 : 10b6 : a03 : If c : : 19)  with 
Microsoft  SMTP  Server  (version=TLSl_2 , 

c i phe r-jrl S^_EC'DHE_RS A_W  1  T B  AES_256_GCM_SHA384 )  id  15.20.3131  .20;  Tue,  30  Jun 
2020  13:25:32  +0000 

Received:  from  DM2GCC01 FT007 . eop-gccOI .prod. protection . outlook . com 
(2a01 : 111 : f 400 : 7d01 : : 200)  by  MWHPR09CA0028 . outlook, off ice3 65 . com 
(2603 : 10b6: 300 : 6d: : 14)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher-TLS_ECDHF,_RSA_WTTH_AES_256_GCM_SHA384 )  id  15.20.3153.20  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:25:32  +0000 
Authentication-Results-Original :  spf  scftfail  (sender  IP  is  162.217.184.79) 
smtp ,mailfrom=cookcountyil . gov;  cookcountyil.gov;  dkim=none  (message  not 
signed)  header . d=none; cookcountyil . gov;  dmarc=fail  action=none 
header . from  ••ccokcountyi 1 . gov; 

Received-SPF:  SoftFail  (protection.outlook.com:  domain  of  transitioning 
cookcountyil .gov  discourages  use  of  1 62. 2 17. 184. 79  as  permitted  sender) 
Received:  from  CCCASV01.CCOUNTY.com  (162.217.184.79)  by 
DM2GCC01FT007  .mail  .iprotection.'outlook. com  (10.97.3.159)  with  Microsoft  SMTP 
Server  ( versio$«$£§l_2 ,  ciphes=TLS^OBSE_RSA_WITH__AES_128_GCM_SHA256)  id 

15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:25:31  +0000 
Received:  from  CCCASV02.CCOUNTY.com  (10.124.40.40)  by  CCCASV01.CCOUNTY.com 

(10.124.40.39)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 

cipher=^rLS_ECBHE_RSA_WITR_AES_128_GCM_SHA256)  id  15.1  .1261  .35;  Tue ,  30  Jtp 
2020  08:24:59  -0500 

Received:  from  GCC02-BL0-obe.outbound.protection.outlook.com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 
15.1 .1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:24:59  -0500 
Received:  from  BN6PR09CA0054.namprd09.prod.outlook.com  (2 603 : 10b6 : 404 : 7a : : 16) 
by  SA9PR09MB5439.namprd09.prod.outlook.com  (2603 : 10b6 : 806 : 47 : : 13)  with 
Microsoft  SMTP  Server  (version-TLSl_2 , 

cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3131.21;  Tue,  30  Jun 
2020  13:24:56  1 0000 

Received:  from  DM2GCC01FT008 . eop-gccOI .prod. protection . outlook.com 
(2a01  : 1.1 1  :  f 400  :  7d01 :  :  206)  by  BN6PR09CA0054  .  outlook. of fice3 65  .  com 
(2603  : 10b6  :  404  :  7a :  :  16)  with  Microsoft  SMTP  Server  (vers  ion-TLS1._2 , 
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3131.20  via  Frontend 
Transport;  Tue,  30  Jun  2020  1  3:24  :56  1 0000 
Authentication-Results-Original :  spf=softfail  (sender  IP  is  162.217.184.79) 
smtp. mailf roitir^dbdkcountyii-, gov;  cQokc0untyil.gov;  dkJjjMnsiie  (message  not 
signed)  header .  d-nohe ;  cookcountyil  *  go-V;  dmarc=fail  act  ibt+f  none 
header . f rom=cookcountyil . gov; 

Received-SPF:  SoftFail  (protection . outlook . com:  domain  of  transitioning 
cookcountyil.gov  discourages  use  of  162.217.184.79  as  permitted  sender) 
Received:  fromCCCASV02.CC0UNTY.com  (162.217.184.79)  by 
DM2GCC01FT008.mail.protection.outlook.com  (10.97.3.193)  with  Microsoft  SMTP 
Server  (version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 

15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:24:55  +0000 
Received:  from  CCCASV02.CCOUNTY.com  (10.124.40.40)  by  CCCASV02.CCOUNTY.com 

(10.124.40.40)  with  Microsoft  SMTP  Server  (version -TI, Si  2 , 

cipher=TLS_ECDHE_RSA_WITH_AES_12 8_GCM_SHA2 5 6 )  id  15.1.1261.35;  Tue,  30  Jun 
2020  08:09:48  -0500 

Received:  from  GCC02-BL0-obe.outbound.protectioniOUtlOok.com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 


(version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 

15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jan  2020  08:09:48  -0500 
Received:  from  CY4PR09CA0074.namprd09.prod.outlook.com  (2603 : 10b6 : 903 : c7 : : 12 ) 

by  MW2PR0901MB3819.namprd09.prod.outlook.com  (2 603 : 10b6 : 302 : 6 : : 17 )  with 
Microsoft  SMTP  Server  (versIon=$LSi_2,; 

cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384)  id  15.20.3131.24;  Tue,  30  Jun 
2020  13:09:37  +0000 

Received:  from  DM2GCC01FT007 . eop-gccOl .prod. protection . outlook.com 
(2a01:lll:f400:7d01: :201)  by  CY4PR09CA0074.outlook.office365.com 
(2603 : 10b6 : 903 : c7 :  :  12 )  with  Microsoft  SMTP  Server  (versioh=TLSl_2 , 
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384)  id  15.20.3153.20  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:09:37  +0000 
Authentication-Results-Original :  spf=softfail  (sender  IP  is  162.217.184.79) 
smtp .mailf rpm— d&okcountyii , gov;  eookeonntyil . gov;  'dkim^n'QB.6  (message  not 
signed)  header  . d  -none;  cookcountyil  .  gov;  dmarc=fail  a e t i on  ='n 6 r, e 
header . f rom=cookcountyil . gov; 

Received-SPF:  SoftFail  (protection, outlook. com:  domain  of  transitioning 
cookcountyil.gov  discourages  use  of  162.217.184.79  as  permitted  sender) 
Received:  fromCCCASV01.CCOIMTY.com  (162.217.184.79)  by 
DM2GCC01FT007 .mail, protection, outlook. com  (10.97.3.159)  with  Microsoft  SMTP 
Server  (version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 
15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:09:37  +0000 
Received:  from  CCCASV02.CCOUNTY.com  (10.124.40.40)  by  CCCASV01.CCOUNTY.com 
(10.124.40.39)  with  Microsoft  SMTP  Server  (version  -T'LSl  2 , 

cipher=TLS_ECDHE_RSA_WITH_AES_12 8_GCM_SHA2 5 6 )  id  15.1.1261.35;  Tue,  30  Jun 
2020  08:08:30  -0500 

Received:  from  GCC02-DM3-obe . outbound . protection . outlook . com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(ver:sion--TLSl_2  ,  ci  pher  T'LS_ECL)HE_RSA_W  ITH_AES_1  2  8_GCM_SHA2  5  6 )  id 

15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:08:30  -0500 
Received:  from  31,2 PR09CA0006 .r.amprd09 . prod.outlook.com 

(2a01:Jil:e400:c743: :16)  by  BY5PR09MB4181 .namprd09 . prod.oUtlook.com 
(2603 : 10b6 : a03 : ld8 : : 9)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher=TLS_BCDBE_RSA_WITHjAES_256_GCM_SHA384)  id  15.20.3131.20;  Tue,  30  Jun 
2020  13:08:28  +0000 

Received:  from  DM2GCC01 FT005 . eop-gccOl .prod. protection . outlook . com 
(2a01:lll:f400:7d01::206)  by  BL2PR09CA0006.outlook.office365.com 
(2a01 : 111 : e400 : c743 : : 16)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher=:TLSMEGDBE__RSA_WITEj8£S_2 5 6_GCM_SHA3 8 4 );  id  15.20.3131.20  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:08:28  +0000 
Authentication-ResUlts-Original :  spf  softfaj.l  (sender  I ?  is  162.217.184.79) 
smtp ,mailfrom=cookcountyil . gov;  cookcountyil.gov;  dkim=none  (message  not 
signed)  header . d=none; cookcountyil . gov;  dmarc=fail  action=none 
header . from -cookcountyil . gov; 

Received-SPF:  SoftFail  (protection.outlook.com:  domain  of  transitioning 
cookcountyil . gov  discourages  use  of  162. 217. 184. 79  as  permitted  sender) 
Received:  from  CCCASV01.CCOUNTY.com  (162.217.184.79)  by 
DM2GCC01FT005 .maiitprotectioh. outlook. com  (10.97.3,0)  with  Microsoft  SMTP 
Server  (versio*n=TLSl_2 ,  cipJie,t=TLS-EC'DRE_RSA_WITH_lES_128_GCM_SHA256)  id 
15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:08:28  +0000 
Received:  fromCCCASV02.CC0tlNTY.com  (10.124.40.40)  byCCCASV01.CCOUNTY.com 
(10.124.40.39)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher=TLS_EC0I&'  RSA_WITH_AES_128_GCM_SHA256)  id  15.1,1261.35;  Tue,  30  Jun 
2020  08:08:19  -0500 

Received:  from  GCC02-DM3-obe.outbound.protection.outlook.com  (10.124.186.250) 
by  CCCASV02.CCOtlNTX.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 

15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:08:19  -0500 
Received:  from  BL0PR0901CA0022.namprd09.prod.outlook.com 
(2603:1 0b6:208:lc0::32)  by  DM6PR09MB5639 . namprd09.prod.outlook.com 
(2603 : 10b6: 5 : 261 : : 18)  with  Microsoft  SMTP  Server  (versLan«TLSl_2, 
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3131.20;  Tue,  30  Jun 
2020  13:08:17  +0000 

Received:  from  DM2GCC01FT006 . eop-gccOl .prod. protection . outlook.com 
(2a01 : 111 : f 4 00 : 7d01 : : 2 0 3 )  by  BL0PR0901CA0022 . outlook . of fice365 . com 
(2603  : 10b6 :  208  :  IcO  :  :  32)  with  Microsoft  SMTP  Server  (versi®n*=?T,LSl_2, 
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3131.21  via  Frontend 


Transport;  Tue,  30  Jun  2020  13:08:17  +0000 

Au  then  t  i  cat  ion  -Hesu  1 1  s  -Or  igi  na :  spf  softfail  (sender  IP  is  1  62  .2.17 .184.79) 
§mtp. ma i  1  f rgitVfcgokcou at yi  1  gov ;  cookcoiihtyil.gov;  dkiitfsfpdne  (message  not 
signed)  header . d=none; cookcountyil . gov;  dmarc=fail  action=none 
'header .  f  rcm--eookccuntyil .  gov; 

Received-SPF:  SoftFail  (protection.outlook.com:  domain  of  transitioning 
cookcountyil.gov  discourages  use  of  1 62. 237. 184. 79  as  permitted  sender) 
Received:  from  CCCASV01.CCOUNTY.com  (162.217.184.79)  by 
DM2GCC01FT006.mail.protection.outlook.com  (10.97.3.107)  with  Microsoft  SMTP 
Server  (version*Ti,S1_2,  cipher=TLS  ..Ee'PB£_RSA_WITH_AES_128_GCM_SHA256)  id 

15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:08:17  +0000 
Received:  from  CCCASV02.CCOuNTY.com  (10.124.40.40)  byCCCASV01.CCOUNTY.com 

(10.124.40.39)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 

cipher=TLS_ECD®E'  RSA_WIT&jAES_128_GCM_SHA256)  id  15.1,1261.35;  Tue,  30  Jun 
2020  08:08:14  -0500 

Received:  from  GCC02-DM3-obe.outbound.protection.outlook.com  (10.124.186.250) 
by  CCCASV02.CCCUKTY.com  (IQ  .  124 . 40 . 40 )  with  Microsoft  SMTP  Server 
(version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 
15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:08:14  -0500 
Received:  from  BN3PR09CA0048.namprd09.prod.outlook.com  (2603 : 10b6 : 400 : 3 : : 16) 
by  SA9PR09MB5678.namprd09.prod.outlook.com  (2 603 : 10b6 : 806 : Id: : 23 )  with 
Microsoft  SMTP  Server  (ve.rsion-'TLSl_2 , 

cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384)  id  15.20.3131.21;  Tue,  30  Jun 
2020  13:08:12+0000 

Received:  from  DM2GCC01FT009 . eop-gccOl .prod. protection . outlook.com 
(2a01:lll:f400:7d01: :207)  by  BN3PR09CA0048.outlook.office365.com 
(2603 : 10b6 :  400  :  3 :  :  16)  with  Microsoft  SMTP  Server  (versiant=tf'IiSl_2, 
cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 )  id  15.20.3131.20  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:08:12  +0000 
Authentication-Results-Original :  spf=softfail  (sender  IP  is  162.217.184.79) 
smtp .mailf roKi—codkcountyil . gov;  cookcountyil . gov;  dkimwnone  (message  not 
signed)  header .  d— none;  cookcountyil .  gov;  dmarc=fail  action-nor.e 
header . f rom=cookcountyil . gov; 

Received-SPF:  SoftFail  (protection, outlook. com:  domain  of  transitioning 
cookcountyil.gov  discourages  use  of  162.217.184.79  as  permitted  sender) 
Received:  fromCCCASV02.CCOUNTY.com  (162,217.184.79)  by 
DM2GCC01FT009 .maii+protectiOh. outlook. com  (10.97.2.68)  with  Microsoft  SMTP 
Server  (version=TLSl_2 ,  cipher=TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256)  id 

15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:08:12  +0000 
Received:  from  CCCASV02.CCOUNTY.com  (10.124.40.40)  by  CCCASV02.CCOUNTY.com 

(10.124.40.40)  with  Microsoft  SMTP  Server  (version  TLS1,_2, 

cipher=TLS_ECDHE_RSA_WITH_AES_12 8_GCM_SHA2 5 6 )  id  15.1.1261.35;  Tue,  30  Jun 
2020  08:07:55  -0500 

Received:  from  GCC02-DM3-obe . outbound .protection , outlook . com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
(version 'TLS1_2,  cipher^TLS_:-;CDHE_RSA_W  LTH_AES_12 8_GCM_SHA2 5 6 )  id 
15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:07:55  -0500 
Received:  from  BLQPR0901CA0008.namprd09.prod.outlOok.com 
(2603:1 0b6:208:lc0: : 1 8 )  by  BY5PR09MB4136 . namprdO 9 .prod. outlook . com 
(2603 : 10b6 : a03 : ldc : : 9)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher-TLS_EGOSE_RSA_WIT8  AES_256_GCM_SHA384 )  id  15.20.3131.23;  Tue,  30  Jun 
2020  13:07:50  +0000 

Received:  from  DM2GCC01FT006 . eop-gccOl .prod.protection.outlook.com 
(2a01:lll:f400:7d01: :208)  by  BL0PR0901CA0008.outlook.office365.com 
(2603 : 10b6 : 208 : IcO : : 18)  with  Microsoft  SMTP  Server  (version=TLSl_2 , 
cipher«ttS_EGQHE_RSA_WITH__AES_256_GCM_SHA384)  id  15.20.3153.20  via  Frontend 
Transport;  Tue,  30  Jun  2020  13:07:50  +0000 
Authenti cation-Results-Original :  spf  softfail  (sender  IP  is  162.217.184.79) 
smtp ,mailfrom=cookcountyil . gov;  cookcountyil.gov;  dkim=none  (message  not 
signed)  header . d=none; cookcountyil . gov;  dmarc=fail  action=none 
header . from- -cookcountyil . gov; 

Received-SPF:  SoftFail  (protection.outlook.com:  domain  of  transitioning 
cookeouhtyil.gov  discourages  use  of  1 62. 2 17. 184. 79  as  permitted  sendef) 
Received:  from  CCCASV01.CCOUNTY.com  (162.217.184.79)  by 
DM2GCC01 FT006 .mail .protection . out! ook . com  (10.97.3.107)  with  Microsoft  SMTP 
Server  (version<=TLSl_2,  cipher^TLS_ECBSEJRSA_WITH_AES_128_GCM_SHA256)  id 

15.20.3131.20  via  Frontend  Transport;  Tue,  30  Jun  2020  13:07:50  +0000 


Received:  from  CCCASV02.CCOUNTY.com  (10.124.40.40)  by  CCCASV01.CCOUNTY.com 
(10.124.40.39)  wi&&  Microsoft  SMTP  Server  (versioh=TLSl_2 , 
cipher«TLS_EGBBE  RSA_WITHjAES_128_GCM_SHA256)  id  15.1.1261.35;  Tue,  30  Uun 
2020  08:07:25  -0500 

Received:  from  GCC02-BL0-obe.outbound.protectiofi.oytlook.com  (10.124.186.250) 
by  CCCASV02.CCOUNTY.com  (10.124.40.40)  with  Microsoft  SMTP  Server 
( ve  r  s  i  op-TL  Sl_2,  cipher =TLS_E  CDHE_RS  A_W  ['TH_AE  S_1 2  8_GCM_SHA2  56)  id 
15.1.1261.35  via  Frontend  Transport;  Tue,  30  Jun  2020  08:07:25  -0500 
Received:  from  CH2PR09MB4491.namprd09.prod.outlook.com  (2603 : 10b6 : 610 : 36 : : 19) 
by  GH2PR09MB4395.namprd09.prod.aytlook.com  (2603 : 10b6 : 610 : 6d: : 18)  with 
Microsoft  SMTP  Server  (version=TLSl_2 , 

ciph^r-TLS  $CBHE_RSA_WITH  AES_256_GCM_SHA384 )  id  15.20.3131  .21;  Tue,  30  Jun 
2020  13:07:22  +0000 

Received:  from  CH2PR09XB4 4 91  .namprd09.prod.outlook.com 
( [ fe80 ; ;54b4 : la30 : 151b : 810f ] )  by  CH2PR0 9MB4 4 9 1 . namprdO 9 . prod . outlook . com 
(  [fe80: :54b4:la30:151b:810f%5] )  with  mapi  id  15.20.3131.027;  Tue,  30  Jun  2020 
13:07:22  +0000 

From:  "CCS0  Intel  (Sheriff)"  <CCS0 . INTEL@cookcountyil . gov> 

Subject:  Pass  Through.  (U//FOUO)  Criminal  Hackers  Target  US  Law  Enforcement 
Data 

Thread-Topic:  Pass  Through  -  (U//F0U0)  Criminal  Hackers  Target  US  Law 
Enforcement  Data 

Thread-Index :  AdZOUZRVrVUDcf01TiiWh3YEOiFXiAAj  ZyaaAAAHqe8= 

Date::  Tue,  30  Jun  2020  13:07:2.0  +0000 
Message-ID: 

<CH2PR09MB4491104495F32B729B402EA7F56F0@CH2PR09MB4491.namprd09.prod.outlook.com> 
References:  <LYRIS-103909956-141184 6-2020 . 06 . 29-15 . 13 . 38— isp-les- 

north#lists . illinois . govglists . illinois ,gov>,<CH2PR09MB44918DBCA1539E418B6FB17FF56F0@CH 
2.PR09MB4  4  91 .  namprdO  9  .prod,  outlook .  com> 

In-Reply-To : 

<CJI2PR0 9MB4  4  918  DBCA1 5  3  9E  4 1 8B  6FB17  FF5  6F0  @  CH2  PRO 9MB4  4  91.namprd09.prod.outlook.com> 

Accept-Language :  en-US 

Content-Language:  en-US 

X-MS-Has-Attach :  yes 

X-MS-TNEF-Cor relator : 

Authentication-Results-Original :  cookcountyil. gov;  dki?fe=nbhe  (message  not 
signed)  header  .  d-ncne ;  cookcour.ty.il  .  gov;  cmarc-nor.e  act  ion -.n'pr.  e 
header . f rom=cookcountyil . gov; 
x-origir.atir.g-ip:  [162.217.184.194] 
x-ms-publictraf f ictype :  Email 
X-MS-Of fice365-Filtering-HT:  Tenant 

X-MS-Of f ice3 65-Filter ing-Correlation-Id:  ae69832f-1896-462e-8066-08d81cfb2cf 6 
x-ms-traf f ictypedi agnostic: 

CH2PR0  9MB  4395:  | BY5PR09MB4136 :  | SA9PR09MB5678 :  | DM6PR09MB5639 : | BY  5  PRO  9MB4 181  :  | MW2PR0901MB3 
819: | SA9PR09MB5439 : | BY5PR09MB3873 : | BYAPR09MB3189 : 
x-ms-oob-tlc-oobclassifiers : 

0LM: 9508 ;0LM: 9508;OLM: 9508;OLM: 9508;OLM: 9508;OLM: 9508;OLM: 9508;OLM: 9508;OLM: 9508; 
X-Mi.crosoft-Anti  spam-Untr .ustec :  ©CL:.:  0; 

X-Micro soft-Anti spam-Mess age-inf o-Original : 

i+uzE6hVIcnRsGSlQWcn6TsXKHhKrGB2ApYs8WShxLg2Up0u820HRfhsFp+9Cj lQecvSzZCwXpalAW04qrntWsl 
2q6Qw2oMnjCqqmlvLhbB607gMDlp2f 7mBL3QYwDQr+r4wNnGRAC9xe3+5GPOy8gsOxnYC/tzY345eFTIOdpxi8h 
rvmE/ ovgAyrKD2M+aVOHraAlD6YgO/ dp+AIa6uQJHM92dDHc+v9Nmf f f ieN4nF9HU5Sho5Qf aoyzaceI9B/ Iqgk 
rVdj SZovu2pQFCekwDlO j;sQ53n+eomH8b9QGUQEKneL2evj WMOddwOzd2moDdY/WDuTaKA+WaJWmCPWlpQPTj  ZL 
1 592rts6hC4  9p2A- 

X-Forefront-Antispam-Report-Untrusted:  CIP : 255 . 255 . 255 . 255 ; CTRY :; LANG : en; SCL : - 
1 ; SRV : ; JPV : KL I ; SFV : SKI; H : CH2.PR0 9MB4  4  91 . namprdO  9 . prod . outlook . com; PTR: ; CAT : NONE ; SFTY : ; SF 
S : ; DIR: INB; SFP : ; 

x-ms -exchange-anti spam-messagedata: 

BuYbw0RoSBfECmAFs5sfpqFR/eESsNr+Plx06kdsYiyNoXFEYgS3Jz6QYqBwqdalBgTm5iebIlsncXRB6v4+RaV 

C42PE10HwFJB0AzNHKMxkCZCwRxlmubguafevanh98UlGYiSoqtiVFIMyzzqWjVwq2ALgG6TEoWT0D6wL3DHlg+ 

twaRl|DO:5pX7Y3tJUqHuj:3:UkkWpE3g+KMrlKiWDb6hsqAZsExSu0dRsfelbY5iawMgVlP06KM54AE4iNVyJ6s+Ph2 

oFB021MJN0zbzrKRmG5176nAVkDQZ6LAJ59qRaYnm4V2jeg+UrmezaEAlBSTXRnJE7c4PTWoAZR7vsnGJlZPDSr 

wlqBu5V'9fQ0asbFFrSOauG9RYElceEBM32qfNX9W5sCwVf+Z2W+dW0tMy5YgF7ghw6XrerqzMMShABB14TwG3sg 

hMkbytZTnSmqwnqf 05E2cPgyZHNVzIQHTfXbIbLbhC/ uOVat8cAb+pOhONzcOhHtduUMJV/ CgNncT 

x-ms -exchange- t tansport-f or ked:  True 

x-ms -exchange- transport-crosstenantheaders stamped:  CH2PR09MB4395 
x-organi z at ionheaderspre served:  CH2PR09MB4395 . namprd09.prod.outlook.com 


x-crosspremisesheadersf iltered:  CCCASV02 . CCOUNTY . com 
Content-Type :  multipart/mixed; 

boundary ~"_004_CH2PH09MB4  4  91  1  04495F32B729B402KA7F56F0CH2PR0 9MB4  4  91namp_" 

MIME -Version:  1.0 

X-CrossPremisesHeadersFilteredBySendConnector :  CCCASV01 . CCOUNTY . com 
X-OrganizationHeadersPreserved:  CCCASV01 . CCOUNTY . com 
To :  Ondisc.l osed  recipients:; 

Return-Path :  CCSO . INTEL@cookcountyil . gov 
X-EOPAttributedMessage :  7 

X-MS-Exchange-Transport-CrossTenarifc.Headers Stripped:  DM2GCC0TFT006 . eop- 
gccOl .prod. protection . outlook.com 

X-Forefront-Antispam-Report^CJiltcusted.:  C-fP;.162.217 . 184 . 79;CT’M:US;LANG:fn;;  SCL:.-^ 

1 ; SRV : ; I P V : CAL ; SFV : SKN; H : CCCASVO 1 . CCOUNTY . com; PTR : Inf oDomainNonexi stent ; CAT : NONE ; SFTY : ; 
SFS :  (356005)  (8676002)  (33656002)  (34756004)  (9686003)  (45080400002)  (186003)  (19627405001)  (83 
080400001)  (28085005)  (26005)  (81166007)  (86362001)  (7696005)  (2940100002,)  (6506007)  (833804000 
01)  (21480400003)  (55016002)  (109986005)  (52536014)  (8936002)  (1096003)  (166002)  (82310400002)  ( 
336012) (5660300002) ; DIR: 1KB; SFP : ; 

X-MS-Of f ice3 65-Filter ing-Correlation-Id-Prvs :  032 05142-5 935-4a88-f6ba-08d81cf 68713 
X-Mi  crosof  t-Antispam-Untrustec  :•  BCL :  0; 

X-Mierosof t-Ahtispam-Message-Ihfo-Original :  =?us- 

ascii?Q?lYLt41z j  ohYSlUQWgv06t91rCCqmdNXNGL/lZqlPhd8tDb34+hVkCmKj  Qgwb?= 

=?Us -ascii  ?Q?lE0v2qaDx+Ws  LhCBH/P  6  Fq  I  GXDyGtPXI + a  5  9  WXVg  1 8  wHNZiiT  DW  4  e  zihvX  /  C  /  ?~ 
=?us-ascii?Q?C5QWIwGl jMZ9nNide/BsVAQCvRtiOiBwMJz JgBHWppSXiCqkYXvAj VrFnthB?= 
=?US-ascii?Q?/lELoNNBfU9g$fGdSrA4hMYtLJGI3ZPcIMU3mertlD3yhJUsfS'76hl7dLvwhpf= 

=  ?us-ascii?Q?obmlOpUj  8 JfbMLumE4IOLNi3SRsSiKMXR184tmPxFOZLtLLQAb5L9QyUIRGj  ?= 
=?us-ascii?Q?AfagIBxOE8rFB7FQ7Tmiso+NUhQlVuQ2CsnbGOtQXYw6kOW7j4L2SpghokBq?= 
=?us-ascii?Q?snBb4X+vH3byJAS3RBbnw8FUqDwl9bffiTbypLZW/ATea7NKqtwh2NL9ulpmGR?= 
=?us-ascii?Q?SOKVOBDB106C8xcScJqRr6TMd6f / QSG9RS/ o5mY8sLeW4QUgPRdc+19G9U8i?= 
=?us-ascii?Q?xghOCllmeXsOOPAvFGOqUuHuq98fuK/h3dJe4ol91dndrl25/ZrD5/mM5tMU?= 
=?us-ascii?Q?Cika3DJc6ThxpEhVk9eP0XF3vXsSyLh/51VqggK7qdIo9Or4L+EytEBmagiP?= 
=?us-ascii?Q?90IvfBUZOTqvL+YXRh5Tt;hlNKY2KnaVm4ZEIZZIsappdmRlfbX+8j:wfaClt5?- 
=?us-ascii?Q?Mvy6KqTV7nvG67X+4:sZUlUYJU10pWnelosGHA2cKePDx2irAzAo8+CfMuHMd|:- 
=?us-ascii?Q?VLPTAEvFysFos Jbqc8KyJ9bAGPILhmxmPOt JSxgl08Y094MHpb8WFSt8Yc0H?= 
=?US-ascii?Q?J4j  9Puchb64  2Tgo7/H5YBoydy6KVYc0H ci qpM/w20pXyLDj  H'  I cPYC I AxAobp?" 
=?us-ascii?Q?bNbiYMYfeW6InJRy6J5FW9UOBuhpSD8hW5nL4XrqLTXTlANdkZuSZGM/ia8s?= 
=?US-ascii?Q?dFg+kVtAn6Dw/ aJj ODLtgFC+ddjmWFkqs JvSRiQhUVNR9l JKn7T984YX0LM3?= 
=?US-ascii?Q?Hv+6+vtPrSi+©CE5A3wynhr+LiTnpObCZ48EEHmqqth6RqHH094c+Kvyy98E?- 
=  ?us-ascii?Q?l3n3ipWylznaSwyRpDpXq5Gltc2ltHj wxa/sKDf Z4Z5XaQj  JPpgv5GdDqlyr?= 

?us-ascii  ?Q?kkb0rVr63pPAcpNI,ufGDr.ekFCMrUl  2CenZmbYwKHR0jdtl  CWZ.Gj  P4  7fvj8pU?” 
=?us-ascii?Q?u9H4IvI JEsgVHua/lah2OG865xn68nQdfx+rdKlA34m+O0nnmZT7I6nrGWhp?= 
-?us-ascii?Q?2cCqDlyKKbI9vRaAmGMYDUJjh937oq9QdOJZptg-,3l}-3D'?= 
X-MS-Exchange-Transport-CrossTenantHeadersStamped:  BY5PR09MB4136 
X-OrganizationHeadersPreserved:  BY5PR09MB4136.namprd09.prod.outlook.com 
X-CrossPremisesHeadersFiltered:  CCCASV02 .CCQUNTY.com 
X-CrossPremisesHeadersFilteredBySendConnector :  CCCASV02 . CCOUNTY . com 
X-OrganizationHeadersPreserved:  CCCASV02 .CCOUNTY.com 

X-MS-Exchange-Transport-CrossTenantHeadersStripped:  DM2GCC01FT009 . eop- 
gccOl . prod .protecti on . outlook.com 

X-Foref  ront-Anti  spam- Reporfe'-'Oct  bus  ted:  CIP :  162 .217.184. 79;  CTRY  :US ;  LANG:  en;  SCL :  - 
1 ; SRV : ; IPV: CAL; SFV: SKN; H : CCCASV02 . CCOUNTY . com; PTR: Inf oDomainNonexistent; CAT : NONE; SFTY : ; 
SFS:  (5660300002)  (83380400001)  (6506007)  (45080400002)  (186003)  (9686003)  (55016002)  (336012)  ( 
7696005)  (34756004)  (28085005)  (26005)  (109986005)  (8676002)  (166002)  (2940100002)  (21480400003 
)  (52536014)  (81166007)  (86362001)  (82310400002)  (83080400001)  (19627405001)  (1096003)  (8936002 
)  (33656002)  ;  DIrR:XM3;SPp«.; 

X-MS-Of fice3 65-Filter ing-Correlation-Id-Prvs :  87167387-01ce-46e6-dbb8-08d81cf 6977c 
X-Microsof t-Antispam^Uutrusted;  SCL: 0; 

X-Microsoft-Antispam-Message-Info-Original :  =?us- 

ascii?Q?80irdlrP+4M92l3rarYwhqR8i7U86kRgTKTpoySUWUyssajlzkCeqYYN0uYU+?= 
=?us-ascii?Q?3QuYqtfaRvlsoOEriADWywpccebe3ILn7BRHmi69S8svxONn3HC5/nVlfhJ3?= 
=?us-ascii?Q?Y7bDDoU9 j AOXvd7tG9tRMlTNiZtcs5kbYdc+TduZXYeFbGUZhAAM02ovvHin?= 
=?Us-ascii?Q?4lKFlqrIjinco91z55 JWEc+ JYv5FQ7HyqpDym4N8GbuJ3m969QQxizQ+Ru/V0?= 

=  ?us-ascii?Q?3YQGzNpg9ACRBgCT j  xd+2xQqDD+W7aW8Wy06SV4TpqtlT4Qt6ovBvlqE+gad?= 
=?US-ascii?Q?apndIlF4CAMFKDakZlRXBUC4'U0K4f H6nAy7ZlGLBDahlOL/av+lFxGyBUYvxJ= 

=  ?us-ascii?Q?j  ZprMhtwvHmg/ 3VuLiuzeOQ/ qklHNFtUX7m7aQj VhJodpD7P j  PkGTWveDbmF?= 

■  Yus-ascii  ?Q?Ayx63s05wC0VYQYi  QCXfRaBtmJMCQez.NOZO:i  vI,:-.gJyk3m7z.KZT01nmkdj  SZV?^' 
=?us-ascii?Q?Mj  Dgs9HClINF3xd0cgl  1 5  K  z  Oc  2  vAS  P  3  9  y  X  Su  D  z  n  L  N  W  6  DNX  kM2  mo  P  t  q’r.  N  3  z.  f  R  ? 
=?us-ascii?Q?t+R8TTMR+kc/kt5T+qi3YMMolCHUEqZagUZged48yWjp3IFRBTduhmv5vyU9?= 


=?us-ascii?Q?R/QVoaoqlLuVUWpakQTA9mmYlbR409tUofmD6b6/q7DVTRC84QPpytyLfigX?= 
=?US-ascii?Q?ZE8cR5mDpEOHolDOgwFkBXTOUwt2c2+QlFFCr35uo+eQuGXdfG/rOG6IBRzJ?= 
=?us-ascii?Q?0ix07aUA/dhmckBxZxdVMfLwa3uLpYXwHTo4fDh31 JTx2|USv7SwzmIsgrlC6?= 
=?us-ascii?Q?/GLOKIiynnX4Q5uh514GfKuy3cUXJbS3ymWRhYAhgoIMNh31ZyKBKnMFzpOD?= 
=?us-ascii?Q?XLeY4kGvXf7gYULJOgCwoGZtl5FanF2f6BRNtvQqifPIQu3JphDOGE/3Zqm4|= 

=  ?us-ascii?Q?uv3EZsuVjHDj  PdODb3WIoyHcZkLxFMFsua6oTOQwpsrONKOXFQcovh2z8Lyw?= 
=?US-ascii?Q?P/4BIPW6bHiERatfLr5WWzliI9aLsPlSwir3esH61MLCpY0eXKZldwdKwoHc+?= 
=?us-ascii?Q?uU97YqHOweP/CdV2EJtrdJJKJ6SYpGpcz+R6g3zIvCVGnekdsfQLZf jPGx9v?= 
=?us-ascii?Q?bTlh7a/zI0EeMJmTFKpCTo3d5zSZJHXhldAqFR6xEKI3WqqP+V4pS2o5VuP0?= 
=?us-ascii?Q?AzmQZUZ8Rti7hkQf  5Vwl7  38DqhxUNHVbln8AnM4rpR29AlxX8IVtTXlFuwuyX:f— 
=?us-ascii?Q?CeHOyAzlm95KOoSwEx2a6+epAPGCZT+oKHodRg=3D=3D?= 
X-MS-Sxchar.ge-Trarsport-Cross'I  er.antHeadersStamped:  SA9PR09MB5678 
X-Organi z at ionHeaders Preserved:  SA9PR09MB5678 . namprd09.prod.outlook.com 
X-CrossPremisesHeadersFiltered:  CCCASV02 . CCOUNTY . com 
X-Cross?remi  se s Header s  H'i  1  teredBySer.dConr.ecoor :  CCCASV01 .  CCOUNTY  .  com 
X-OrganizationHeadersPreserved:  CCCASV01 . CCOUNTY . com 

X-MS-Exchange-Transport-CrossTenant.Headers Stripped:  DM2GCC01FT006 . eop- 
gccOl .prod. protection . outlook.com 

X-Foref ront-Anti spam-Report nttet rusted:  Cl ? :  162 .21  7.1  84.7 9;  CTRY :US;  LANG: en;  SC L :  - 
1 ;  SRV : ;  LPV; CAL ;  SFV :  SKN ;  H :  CCCASV01 .  CCOUNTY .  com;.fiTR jlnf  oDomaifiNonexi s tent ;  CAT  :NGNE ;  SFTY :  ; 
SFS :  (33656002)  (21480400003)  (52536014)  (2940100002)  (86362001)  (5660300002)  (83380400001)  (33 
6012)  (26005)  (83080400001)  (166002)  (6506007)  (34756004)  (28085005)  (1096003)  (8936002)  (867600 
2)  (82310400002)  (7696005)  (186003)  (45080400002)  (81166007)  (356005)  (9686003)  (55016002)  (1962 
7405001) (109986005) ; DIR : i NB; SKP : ; 

X-MS-Of f ice3 65-Filter ing-Correlation-Id-Prvs :  Iaf24fbe-ca47-444d-331d-08d81cf 6a495 
X-Microsof t-Antispam-Untrusted :  BCL : 0 ; 

X-Microsoft-Anti spam-Mess age- Info-Original :  =?us- 

ascii?Q?d9dMEt6+zcNTF+V4eNF/ sxelvQRbdt/ OG160xLwXKaX6IQf o9ruQQdVNj  SmH?= 
=?us-ascii?Q?iAl4GyTgx4  3ecgePx8 j  o89W+wByJ8 jqXMWC47nQ0rY\6TdIlP2MBv5fyPwBcz?= 

=  ?us-ascii?Q?xAc4qvlUyVrthQnBWlCYer6oZRYuPQbwrRvkBLleWOPBj  J4UtkBQf Jo+rOvr?= 

=?us -ascii  ?Q?qnsBP3hauSorAZKN+YqZlCYgiisivP:/YuhxUQicikiI)/llW4a¥liPKZQ.7Lr5:RZ:9?~ 
=?us-ascii?Q?v/jEEilCsU87POaEJw8HRmOqM+QpxayOSMPCpM5+lxnRVlzs3CGJwr+JB9Br?- 
=?us-ascii?Q?QSgttEN/TLq/aZ8LOuXTPFpvBGgLERFtRHWu/CjtKUb8BW7u6aWdYUNmJyYl?= 
=?US-ascii?Q?uOsyll^PFcgNP238j7  0QtIErZ+HNNiy8ATjZmqEAEdTD3A8ZN:ilX6OLT8I4  4G;f= 
=?us-ascii?Q?f JIOi5s+R42n8hHTkHx7uIciIWtOhixKVqvij7h8Y+ozQA4Pr+E3QYZtIzEK?= 
=?US-ascii?Q?/ARPJJQIGzrN0ue4gcDNE]3lQeug5AEvaW+lbz j 8 1 ZR4  h?VpgyA7  xd Yf p i yFh  ?  •  - 
=?US-ascii?Q?PmIab8hznaH8m+bm3+hXFDbpfVrz3+lt8sRt77QNyDr28WUjlcQ65q/ayc5A?= 

=  ?us-ascii?Q?XSqMNyNINc4gGT j  gj  z2Ts JgrtBEzY8mwb7  +  06Zvt0byqHSKXJlH0OQj  gj fxk?= 
=?us-ascii?Q?VX56BxMANMc7oysb01ECuUmGHLavNa3 jn9kl+HsgB'8aF9Cza5qsu8BgubBNy?= 
=?us-ascii?Q?ywj /c/cxp6Tg8TwRbD2qC3na5kSMETJnnEoFcOVkxSpYcb8wz5eRH7IvpLkt?= 
=?us-ascii?Q?DBhgbfZfIghEthUnTpqmhot4b5q,rN2kSKxd2idFGbdy0fHV4kN4U3VPB60bh?= 
=?us-ascii?Q?qc30ZiTXWbBtP0Fbp98K/QrN69YDoz4T8J06gnVFw6dPOMpQkZyECB+wzZ0h?= 
=?us-ascii?Q?YDLUn6EFGzDnsMglaB7F/xWmYWoo8CVjAnHgGBWR3mHWKyymX4FvTPjmiyK8?= 
=?us-ascii?Q?6igMckgb63ERixgZ9Woxp7JX3wnQc4ygqzpFOWdhiJCyt9R,/UB/oaMl6tgrLfi=;- 
=?us-ascii?Q?/+SiCU28VPq/X3+Kbf++MQ49EFL4R9nZXgN3gXNAfl/hGCy6WN3GxCz05soB?= 
=?us-ascii?Q?iHtDQVqxhdh2:N3uHBNWIQbAfv8niSLUMjhj lvC/18Y3CT4wvXRuSNQVQIPhs?= 
=?us-ascii?Q?dWuOAdnOwcskT2khrdJwrv4 jdkng7qFxl7XlzQGx96ollVZOcQyQxndcaX7i?= 
=?US-aseii?Q?tm8HXuU3v3to8TA6P/lKFfKu9Els09Aj qyOFYQ=3'D=3D?= 
X-MS-Exchange-Transport-CtossTenantHeaders Stamped:  DM6PR09MB5639 
X-OrganizationHeadersPreserved:  DM6PR09MB5639 . namprd09.prod.outlook.com 
X-Cross Premise s Header sl'ilte red :  CCCASV02 .CCOUNTY.com 
X-CrossPremisesHeadersFilteredBySendConnector :  CCCASV01 . CCOUNTY . com 
X-Organi zar ionHeaders Preserved :  CCCASV01 .CCOUNTY. com 

X-MS-Exchange-Transport-CtossTenantHeadersStf ipped:  DM2GCC01FT005 . eop- 
gccOl .prod. protection . outlook.com 

X-Foref ront-Antispam-Report-Uiitrusted:  Cl.?:  1 62  ^21  7 . 184 . 7  9;  CT’RY : US ;  LANG : en ;  SCL;  - 
1 ; SRV : ; I P V : CAL ; SFV: SKN; H : CCCASV0 1 . CCOUNTY . com; PTR : Inf oDomainNonexi stent ; CAT : NONE ; SFTY : ; 
SFS:  (19627405001)  (336012)  (109986005)  (7696005)  (34756004)  (52536014)  (8676002)  (83380400001) 
(28085005)  (86362001)  (186003)  (6506007)  (8936002)  (1096003)  (33656002)  (45080400002)  (21480400 
003)  (55016002)  (9686003)  (26005)  (166002)  (356005)  (5660300002)  (2940100002)  (81166007)  (823104 
00002)  (83080400001)  ;  D LR:  1  NB.;  SFP :  ; 

X-MS-Of fice3 65-Filter ing-Correlation-Id-Prvs :  f 8e8296f-9d4d-4f 39-aee8-08d81cf 6a7d0 
X-Microsof  t-'AntispamfrUntrusted:  BCL :  0; 

X-Microsoft-Antispam-Message-Info-Original :  =?us- 

ascii?Q?RkGcQjZPrbQlXolBDlYvtuGzhkuLTuNhZQrFzlseHTbdDpv/5Fad6wBkKYKE:?= 
=?us-ascii?Q?eNu014KgjHJE+uj  +RrgQxnf4q0bSH28eqWZ|Lxhla7m3O7/8RfpHfjizn5DtPy?~ 

=  ?us-ascii?Q?meKzBUZ j  Y2QZ+nPl+BfGIsZFDAvOFi5KvMK5uT2CLcbKHk+ j  o4/3NH80vHla?= 


=?us-ascii?Q?aS7VKnUuMYxl8UuA4qI/0S+/kYhC00LtDMtKXdPtelfQ/vdqqv9011jox3yR?= 

■  :?'js-asci  i  ?Q?x3oHzYiugiBV5373'K+  iXpf  d/,bqUTkcQioI9/F351  / 3 /  j  /  J815mwHCM8o4Re9?= 
=?us-ascii?Q?zSixr8  JSSytBVn8+WFfWovh9kpyQD'Vij561P97i2MluQXl3Qfklnf®Bl  juM6?= 
=?us-ascii?Q?eohhgKKLRmTZUyB7MiYIsaZ J98P0yntbISW938tf 5uah0yag6wnRUr4UTO7O?= 
=?us-ascii?Q?0FxX8U/Z08p0xGlI4mNPTT6x30.30kBStfDFSU86dynJtbsvzbbTMqxPRLS+2Wf= 

=  ?us-ascii?Q?yxHS9pBfwsFeehFexZWxf PcVOGBNKxqObMm5eZvCCj  3m6kYC+fYG/llf sW10?= 

■  -?-JS-ascii  ?0?wuzEf QzLF/ 6r2W/ oXMzkAS j  NYlSpZSz3/1  k3uwUVc  JllPtMf  AhORj  DwlR’I'Sm? 

=  ?us-ascii?Q?DiSzWpz/102ZCT4ur42Vj  9keSWmtKlTDKZYFldIxJ3f If T/ qlw8eC+yeaWYq?= 

=  ?us-ascii?Q?DDf fbUMuUkTH/NeUT JvWIif J8nhdZAs6yj  qxm7s4cBN5wATkT3LC9HOFsp41 ?= 
=?us-ascii?Q?bRsPcdqG6cfKwJNTAo++ldPYffdTTlgmRPq3Xf9YkqBQF+3Kj Q+VFOVi5K60?= 

=  ?us-ascii?Q?RAwhDPpZww2yY9ryKetsgunh9qOSUj ieomU/3/0Vrl53pmIEFE/E+90Pwj  Ds?= 
=?us-ascii?Q?dB35R+DvNfM3Ne548dJor8/CIXGZy3vGUiQqLylB/B3BJFX7HCf!ROxEZZrev?- 
=?us-ascii?Q?F/6TbqAFzMlytbNtOxDphpjZgT6hbSbLDqqJppfLyyRT5KBmS3geYRLVx773?= 
=?us-ascii?Q?xnGKwHuoV854HK0ZiRw7rnAIy7Q8sxWnPnIcloxe J6T7dAFC0u/86CeIP4Yl?= 
=?us-ascii?Q?llf sf yPlCyVVKgdRIpem4bVGzve8f +DzASVYsyo3fYL9V8Xz:hl9x97TTnWeT?= 
=?us-ascii?Q?deIfzylz7vYMczFDDjZPI4Q/UNOVGGEsEDOkmX5glly2Db3TB/Ec9oEjfXa6?= 

?us-asci  i  ?O?Y/CN36Aul)a7Er/,0pxCmKLZCkPY7gVxXHx/,zzutveXf  1  RQS6Hf  7NAupyYC?eY?- 
=?us-ascii?Q?HmGYlPQ3gwkHwX3t3XbZ/aCxlzCjUDXjbBKuTg=3D=3D?= 
X-MS-Exchange-Transport”CrossTenantHeaders Stamped:  BY5PR09MB4181 
X-Organizatio&Headers Preserved!'  1JY5PRQ9MB4181 . namprd09 .prod. outlook .  com 
X-CrossPremisesHeadersFiltered:  CCCASV02 . CCOUNTY . com 

X-CrossPremisesHeadersFilteredBySendConnector :  CCCASV01 . CCOUNTY .  com 
X-OrganizationHeadersPreserved:  CCCASV01 . CCOUNTY . com 

X-MS-Exchange-Transport-CrossTenantHeadersStripped:  DM2GCC01  F'1’007  .  eop- 
gccOl .prod. protection . outlook.com 

X-Forefront-Antispam-Report-Untrusted:  CIP : 162 . 217 . 184 . 7 9; CTRY : US; LANG : en; SCL : - 
1 ; SRV ; ; iRVi  CAL ; SFV : SKN ; H : CCCASVO 1 . CCOUNTY .com;  l>TR : Inf oDomainNoaexi s  tent ; CAT : NONE ; SFTY : ; 
SFS :  (7696005)  (81166007)  (9686003)  (83080400001)  (21480400003)  (83380400001)  (52536014)  (89360 
02)  (19627405001)  (1096003)  (8676002)  (55016002)  (34756004)  (186003)  (356005)  (2940100002)  (8636 
2001)  (28085005)  (26005)  (6506007)  (45080400002)  (5660300002)  (33656002)  (109986005)  (166002)  (8 
2310400002) (336012); DIR : JNB; SFP : ; 

X-MS-Office365-FilteSipg-Correlati0a~Id-Prvs:  5605dla4-8015-4690-9cca-08d81cf 6ael9 
X-Microsof t-Antispam-Untrusted :  BCL : 0 ; 

X-Mierosof t^Antispam-Message-Info-Original :  =  ?us- 

ascii?Q?qCN/0rbfLFwlTLD4fUtbJtR3zc4VaK80YxLhMbMHz3GmT61zCJIfwVhh+p4n?= 

=?us-ascii?Q?7 j  rMDTWBwll j+OONOnWfYqvKhwG3eN4IK±iiK17A2H9QcBdwiOwI9Pa52hvrS?= 
=?US-ascii?Q?AQowuTWPTNt2GQ+nRpBQUqnlAouBjCe3Tk8Z¥ncMxF9kgIkC3+RajxHMnQRN?“ 
=?us-ascii?Q?/yd7cG/QoLqgU2OAWyXEmqwxX0An7IyeGyjx7RlV5zMaQKsmvAGYLiNK8cEq?= 
=?us-ascii?Q?8Usu/XUPe7Mde8Kpj  61 ZVOJ jujHwSCavj JCkw3PQFzYt3dZvlk5Sdjw08QJm?= 
=?us-ascii?Q?Joty7TM+omQ5U09obKMT0/ZAFjh0ilS8BQctBQJ81slehrdKQ3mLCZu9s3M5?= 
s  ?us-ascii  ?Q?  I K  lG'r.cG  I  CJswXRVQOXoEc  Jy904  AK  t  9Vf  f  TfCcOX9  I  3YaV8Bl  sh/  JB4'h6YTqU?--: 
=?us-ascii?Q?wIlRat8LqLX7jM13SPFFJavDmO3aELmQNGiww0HyfpYfe/WL0sK3l56Gm4jF?= 
=?us-ascii?Q?nA/iohE2vosa9ie0p71xxYM85MlBldPVMY6LryUpO5IPblORFHuVSfals9sy?= 
=?us-ascii?Q? j  68gNQmWeoETTjX2kkgtl4eO+bnlSzM56+IfiDDyOdlX8MkEQlcuJe2eQj  4WFr,= 
=?us-ascii?Q?Pdzzuo3Nw+xPQSLKHgMYDFreYHWBbNzpHOfymH1090bJrxhreHT5tqH/ykOu?= 
=?US-ascii?Q?kYCEg:5+WnY8xfQogsMXlGGBFJJXo6F76cYFWO8z50K3jTawDihUbCIEnyTqp?= 
=?us-ascii?Q?QfVWsseC0rmTD4CJvM7roKhs3DWoyynDGCabh7q+rhuzSMxsrGCC3SP/o5Ol?= 

?us-asci.i  7Q752VZZ+  I  AJMJVjr.vtrTADdoCBkHCk  1  7xOfm4-;r.tYlzgli  I  6j OOmaGGmr.Ww/i/L?'- 
=?us-ascii?Q?cik4WOE«D25b+/PCOYglaMW3tLq;LCRY+QJPGfHillIzPDJTpOTqHp5qy;3ZO0?= 
=?us-ascii?Q?aeM00wBtyRdorHakfScwme9Zl J+90qdnkwDYU7ppESYT5bW0+OQshyXk5pB5?= 
=?US-ascii?Q?+YDlO,Z;hXjRiGnmUe6kUX5+fBRB7  06ABO05B’3n5fe89LL0qsXtZUift8oyGQf  j  j?= 
=?us-ascii?Q?37Vnxbof j w0BpE5Y4NM0fVfVhvMantuUoEqhcwc0yucHIx7so80M6cUrlRsH?= 
=?US-ascii?Q?No.k/WCEUN7hEKeEnAQ3ZtJL/DaoiiNHwXJYC9VMv5KV8T87AQBj+eF+uiqwxW?= 
=?us-ascii?Q?XQq6L107srf 9hpWWQzf 4wCUp6MYC7ho+YRJumrLbZ/y7GZfi5s2tb:kyumwoud?= 
=?us-ascii?Q?D5Ly+xxa0N4frxN5jI7Jy4//Ht6OsXP+kdltZg=3D=3D?= 
X-MS-Exchange-Transport-CrossTenantHeaders Stamped:  MW2PR0901MB3819 
X-OrganizationHeadersPreserved:  MW2PR0901MB3819 . namprd09.prod.outlook.com 
X-CrossPremisesHeadersFiltered:  CCCASV02 .CCOUNTY.com 
X-CrossPremisesHeadersFilteredBySendConnector :  CCCASV02 . CCOUNTY . com 
X-OrganizationHeadersPreserved :  CCCASV02 . CCOUNTY . com 

X-MS-Exchange-Transport-CrossTenantHeaders Stripped:  DM2GCC01FT008 . eop- 
gccOl .prod. protection . outlook.com 

X-Foref ront-Anti spam- Repofffc-'ffijSf rusted:  CIP:  162.21  7 .184.7  9; CTRY : US ;  LANG : en ;  SCL :  - 
1 ; SRV : ; IPV: CAL; SFV: SKN; H : CCCASV02 . CCOUNTY . com; PTR: Inf oDomainNonexistent; CAT : NONE; SFTY : ; 
SFS:  (5660300002)  (2940100002)  (336012)  (52536014)  (26005)  (6506007)  (186003)  (86362001)  (968600 
3)  (19627405001)  (33656002)  (55016002)  (45080400002)  (8676002)  (8936002)  (1096003)  (109986005)  ( 


82310400002)  (83380400001)  (7696005)  (81166007)  (166002)  (28085005)  (34756004)  (83080400001)  (2 
1480400003); DIR: 1KB; SFP : ; 

X-MS-Of flce365-Filterijig-Correlatioi}~I'd-Prvs :  b470eb5f-28c4-417f-f28c-08d81cf 6d76b 
X-Microsof t-Antispam-Untrusted :  BCL : 0 ; 

X-Mi crcscf r-Anti spam-Message-Tnfo-Crigir.ai :  =  ?us- 

ascii?Q?T3hKtGIx9hSul20ZTKGNj 0VS+etWppUeboTni+IPjpGR9mj DvYgVJo4B6aV3?= 
=?us-aScii?Q?3FOMSM9TXGI6YUsK/9+ylWv8C9 JYdjrVUGkhoaoplQSrELQfeinWj WyvWBkX?- 
=?us-ascii?Q?dJ3WaPrXrcb9dncJABdyZthC0vQT9YQfmDMum2WGRSTfh4sF79N90xVbw2hs?= 

=  ?us-ascii?Q?/EfnO+GAkeNkoGOiryqyJ6MMRM2  9uXtPRgEh4LCMZ98FP4Hepl3 j  uSTxTUho?= 
=?us-ascii?Q?Wg56s708aj27yItGGTl72hFgUCh4aqSArmZ3hK’U;l/QWPlq8mIaKANLlBv7TP?= 
=?us-ascii?Q?otc601eB9pJetlcUJXAdrpVE8wcBVKiyhqLMrbwUV7+kiQyq/dWQE2PQeOed?= 
=?us-aseii?Q?sMU864BYdoapxkZ9VkzCvqNDuCTyxwAe9Sh8uTCrdbUZb/YB3uRFTVSpVsdp?= 

=  ?us-ascii?Q?EB04wtrZDhp5whWU8tvkz9YiS0Lf TAH7ntVD7QRuCZORxslAj / GAY7Xj  Ccbs?= 
=?us-ascii?Q?tqkGK9sFcyJO0CR8pYQ3WbjoTxlgG6AuBsCwKoQlATxHikY14rzZY06uGP5mPs= 
=?us-ascii?Q?3Oe3phZ/RTHK2ShZ985N5Agfv8G5zzoyLJO.VvuqBA5ZxJlDa7  8EnqOVWo0I2Sl?=i= 

=  ?us-ascii?Q?8WwCX7  8n2PY52h5zDaTmJ/ nLeToNWWWQDcvuz JlpYgLdpLWPIKnJ9soPVeAx?= 

■  ?us-asci  i?Q?hZl  IRgAKyZJ/2J7AsZFOU3F.KyEBvaUt//4  3B95q5I,r’I  S/e/m  l  lBAgkPqSCQJ? 
=?us-ascii?Q?KWw9+rrEY2kVdZregsOf F3bWbiNZ3mTfUTbBYerf0zh6iqW2CcN098EsNr7F?= 
=?us-ascii?Q?wc+ulHq:17PTTuWwnGV9DRTvo5Fnq;3kSppRLOr9yAgi(zcY3vnj'i5NTlmWvSH4q?= 
=?us-ascii?Q?9XLRJX2ellffIfNlcWa4  6lUaPPFhC+BAYOu9ZcKWBIMXUKf  SK0K6/mPnXCM4?= 

=  ?us-ascii?Q?09ErlNwkKJs6kMRKzoTL+qW3 j ZMY6gJ7  6fqCo6Aj g4oq6mlyFXyg2rzpLeQb?= 
=?US-ascii?Q?Qk+ JdA7  DNBBWHE1 ThC2tzAK 9 Y  3  r  9  6 / HLBbMl 8  T 2 MMnUHQE.2 xfHbjoWfe7FqD?= 
=?us-ascii?Q?MxR82BaCIE9kSPYB8Fxa695QL/jv7+HyGtCE3mfcWhPGC8M=3D?= 
X-MS-Exchange-Transport-CrossTenantHeaders Stamped:  SA9PR09MB5439 
X-Organi z at ionHeaders Preserved:  SA9PR09MB5439 . namprd09.prod.outlook.com 
X-CrossPremisesHeadersFiltered:  CCCASV02 . CCOUNTY . com 
X-CrossPremisesHeadersFilteredBySendConnector :  CCCASV01 . CCOUNTY . com 
X-OrganizationHeadersPreserved:  CCCASV01 . CCOUNTY . com 

X-MS-Exchange-Transport-CrossTenantHeadersStripped:  DM2GCC01FT007 . eop- 
gccOl .prod. protect ion . outlook.com 

X-Foref E@nt-Antispam-Report-Un.trus  ted:  C'l P:-1  62  .-21  7 . 184 . 79;CTRY :US;  l.ANG:en;  SCI. :  - 
1 ;  SRV :  ,*  I-PV :  CAL;  SFV :  SKN ;  H :  CCCASVO 1 .  CCOUNTY .  com;  PTR :  Ir.foDomainNonexi  scene ;  CAT : NONE ;  SFTY :  ; 
SFS :  (26005)  (5660300002)  (109986005)  (45080400002)  (6506007)  (52536014)  (86362001)  (356005)  (81 
166007)  (19627405001)  (82310400002)  (33656002)  (9686003)  (34756004)  (7696005)  (28085005)  (55016 
002)  (83380400001)  (8676002)  (336012)  (186003)  (1096003)  (2940100002)  (166002)  (83080400001)  (89 
36002) (21480400003) ; DiR: 1KB; SFP : ; 

X-MS-Off ice 365 -Filte;£:ifig— Correlation 'Utd—Prvs :  dl6e5075-aa86-4  03a-675c-08d81cf 8fadl 

X-Microsof t-Antispam-Untrusted :  BCL : 0 ; 

X-Mi  crosoft-Anti. spam-Mess age- Info-Original  :  =?us- 

ascii?Q?IglXY3KuW8S9y9/wztnHgRPyMs4iEDSNkiWI3y7xHxVo93hiyXGpfRj PA3td?= 

?us-asci  i  ?Q?nus1  t  QW1  UDlpNZQgf  vl  zysXu  j  c8GcvQI)  1  zk80nLKHqNr.Ss95kxh  I  oSpQdVVZ?  - 
=?us-ascii?Q?5AvK8mdphwny07TPF9AeG514vkZ6D6VTMo/lwiT JJpvXClkFo7ExZf 6wcTWX?= 
=?us-ascii?Q?RrIpzzF8wDGEvkWgo0XPez2Wq8g7IWoDY//vXUtuMrXhFeiEXK4rvToms8IM?= 
=?US-ascii?Q?ci3/erOWDE73YnUOYSdfOilOkllOL+r20G5;gNglBhfflN,Ol.Dd6hGRKdpe3RPeYf= 
=?us-ascii?Q?fUP5oc6WJ9+9ooAyAODtAdSUlWM0/H06hP28VI/6LFuuBICCqELMCp/WlOVk?= 
=?us-aScii?Q?ROUq/2RrMa3qOGl/TtkdldfjPkc8WQefUA/vGn81sAvSYdOhltWvtWDInceI?“ 
=?us-ascii?Q?DBGWlvgqkfeHj Whzs50bDlsdbl8bk0CzIwZiPPo2fvk+uvl0MHrgyfnlSFAh?= 
=?us-ascii?Q?pws JEqNVSmXO0m5q4K+y2K4XTGqt33S/yoAb6vlQlHlO:yxv581kgj  foi/5Ax?= 
=?us-ascii?Q?0gaAhu8fKq4xF107tRPaWGk5a6Yf scqtMa7B7m5GT14  5xFKo J16KKiZs|ilS7  ?= 
=?us-ascii?Q?lbWsuiksA/ xHawumVOp/ CQdyNL+ZvU+T6hGF0FEMwEGGdoW7VxZRWcd/ 2n3n?= 
=?us-ascii?Q?adzvqQl+v82eGD7diXungpNNAJnKSam5edriVT7klOftC9iOhVYOATQybRwW?= 
=?us-ascii?Q?sE5afED2GXCXgnjXt5i2UDwl0zUVNw62RoN43bu2MkKnNpDtvvGbctpMTvGt?= 
=?US-ascii?Q?iyY8PWj:TlOKuSLSuKafWfslIAf/7S8HlHdlirgJQTRvghMlsWg+p4  7mOs0:fH'il= 
=?US-ascii?Q?DzvkhS6FdjUs7zGw/bj  lSWjR5Tbqgj  6rpel9XlYU8RlFKSC7MQ95uRlIBBfaf= 
=?us-ascii?Q?DS08UKWrHxCpiuRneDw5zIYh+Nzv6XsUPvAI4xa7o5IO4TdCYhhvL3Y17xDD?= 
=?us-ascii?Q?fKfvnEF4uPF4B2MDw+dl3ilZBV5gtiPpG9LlfuFTdS66F6JE.UFnjdcSagHC0T?;- 
=?us-ascii?Q?ERrnrFXpeDOzvCQTPtDxmu3eBORUhwneQAoWMEzelppU59s=3D?= 
X-MS-Exchange-Transport-CrossTenantHeadersStamped:  BY5PR09MB3873 
X-OrganizationHeadersPreserved:  BY5PR09MB3873 . namprd09.prod.outlook.com 
X-CrossPremisesHeadersFiltered:  CCCASV02 . CCOUNTY . com 
X-CrossPremisesHeadersFilteredBySendConnector ;  CCCASV01 . CCOUNTY . com 
X-OrganizationHeadersPreserved:  CCCASV01 . CCOUNTY . com 

X-MS-Exchange-Transpor t-CrossTenantHeadersStf ipped:  CY1GCC01FT010 . eop- 
gccOl .prod. protect ion . outlook.com 

X-l'oref  rone  -  An  t.i  spam- Report:  CIP:  2  62 . 217 . 1  84 . 7  9 ;  CTRY :  US ;  LANG :  en ;  SCI :  - 

1 ;  SRV : ;  1FV :  CAL  ;  SFV :  SKN ;  H :  CCCASVO  1 .  CCOUNTY  .com;  PTR  :;Inf  oDomainNonexi  stent;  CAT :  NONE ;  SFTY : ; 
SFS:  (82310400002)  (52536014)  (45080400002)  (83080400001)  (186003)  (166002)  (336012)  (214804000 


03)  (7696005)  (26005)  (6506007)  (33656002)  (81166007)  (356005)  (1096003)  (5660300002)  (196274050 
01)  (8676002)  (2940100002)  (9686003)  (34756004)  (28085005)  (8936002)  (55016002.)  (109986005)  (833 
80400001) (86362001) ; DIR: 1  KB; SFP : ; 

X-MS-Of f ice3 65-Filter ing-Correlation-Id-Prvs :  5dl4c9be-9361-48a6-1567-08d81cf 9103c 
X-Mi crcsof r-Anti spam:  BCL : 0; 

X-Microsoft-Antispam-Message-Info :  =?Windows- 

1252  ?Q?f Cw9VhR2VvpATVtZy94yo.opg j e HvLIGoycDB'L'2 6  I.  lu2Psoc 9 1 7 DUwRW / ? 
=?Windows-1252?Q?uZGAvccy0Dt5KyvefBfN5ktQ7AJg3UCqfdpPDxOSBGjBO2nZRc6a4Sck?= 

=  ?Windows-12  52  ?Q?nEhC4mbwaTcFyzHI j  KINizpM541EUydvBOj  TFBnSNBMOq5bYnHUyWwUz?= 

=  ?Windows-12S'2?Q?iT0aG3FF+GW4plGVLHRwU66MBiSirj/anqi9xYZo+GJcXTEYg80Cjyc/Wf= 

=  ?Windows-12  52  ?Q?7FAd4PbDpKNZV4zd+Yj  Qwo8hcFTtb5i3mEQMA/bPBJaxwQ7vr8gqPoQl?= 

?Wi  ndows-1252?Q?terX  I  ahr.pl  ak0zUGc4/.9X?7dGny/2tV6PaBkxTo1  Dul,sdQbr./MsqA4E3? 
=?Windows-1252?Q?6gDMmOnISXFrBesq9TfhNqVRDJw2kZC8ijSs/loE5hTtc9NhOJSl/Q7R?= 
=?Windows-1252?Q?qj  Srm/xf  j;:lw6x2sdDZKQsur5t0wvvFhy/AO9/19pI4YxqueZQYA4sDQA?= 

=  ?Windows-i252?Q?AuOT;/CIq7VXcmcquWfWURQpDiLdldECejz41AwvCzitCCCHRZq8B.PkrX:?;= 
=?Windows-1252?Q?FmZnN/2rZ/cbmPJIasu8oI2MbDcSUrM3nvnQvXrdE5b6Zaza2mUlKhIs?= 

=  ?Windows-1252?Q?8hCbdk+rr3uzpxPxB}£lJi0xlq36lS0Qj  196KDwl  03X5tU2yJ  SslHRHrgA? 

=  ?Windows-12  52  ?Q?lzlwzdwQVedKLdTQA4ykOrplWpKxqj  xsKWClnYwk/ESEPylOgT5hQYVb?= 
=?Windows-12S2?Q?zuorbXQUJoaqaZR3PktG0BbPyVJcdM8uJeHwB9sWmv8fkQ5EfYGIFroR?'~ 

?V\iindows-1  252?Q?CZmPq'L’rppYSSFuZgjeljmvxvqm7.RcDl36h+U2 4fU6HR/NklZriuIz,BnVv?= 
=?Windows-1252?Q?jHH7UlPEJQuG91/j9wMF/wOhvHt6JbtlKbZPnOYINFZYfRtTdJ4s8K78?= 
=?Windaws-1252?Q?u40OO118YZtGOg5F8W07yS<3EEbKfittWv/caAHjowc+//JIsbSGuieui4FA?= 

=  ?Windows-12  52  ?Q?5FZzwOUj  GqvCeSyNDO5zzvzO9oYNexlPP8oZsaqSldexscaY1210nzZN?= 

=  ?Windows-l2§2?Q?VgDqZleCdFQmE3Qi.yaBMttB8p7rIj:QpZaiblv/EkbB8wbjxIY4mPycsNQ;?= 
=?Windows-1252?Q?JOugXmc8+OSoyv+4V74nB2/Vf4gMpOc8cSLLDViqC3Hz7J/OYOHS6zJe?= 

=  ?Windows-12  52  ?Q?bVY=3D?= 

X-MS-Exchange-CrossTenant-OriginalArrivalTime :  30  Juri  2020  13:40:38.8976 
(UTC) 

X-MS-Exchange-CrossTenant-Network-Message-Id:  ae69832f-1896-462e-8066-08d81cfb2cf 6 
X-MS-Exchange-CrossTenant-Id:  8b4d55ae-6db4-4e05-a85c-59d6a256cd6e 

X-MS-ExGh.ange-CrossTenant-OriginalAttributedTenantCqiinecfcipgIp :  Tena»tld=8b4d55ae-6db4- 

4e05-a85c-59d6a256cd6e;Ig=tl62,2l7.184.7  9]  ; Helo=  [CCCASV01 . CCOUNTY .. com] 

X-MS-Exchange-CrossTenant-AuthSource :  CY1GCC01FT010 . eop- 

gccOl .prod. protection . outlook.com 

X-MS-Exchange-CrossTenant-AuthAs :  Anonymous 

X-MS-Exchange-CrossTenant-FroifiEntityfleader :  HybridOnPrem 

X-MS-Exchange-Transport-CrossTenantHeaders Stamped:  BYAPR09MB3189 

X-Organi z at ionHeaders Preserved:  BYAPR09MB3189.namprd09.prod.outlook.com 

X-CrossPremisesHeadersFiltered:  CCCASV02 . CCOUNTY . com 

X-OrganizationHeadersPreserved:  CCCASV01 . CCOUNTY . com 

X-Cross  Premises  Header  sK.il  teredByDsr.Ger.e  rater :  CCCASV01  .CCOUKTY.com 


Undeliverable:  Pass  Through  -  (U//FOUO)  Criminal  Hackers  Target  US  Law 
Enforcement  Data _ 


To:  Eric.Sellers@cookcountyil.gov,  Mary.Tamme@cookcountyil.gov, 

Wanda.Barnes@cookcountyil.gov,  Vincent.Gamez@cookcountyil.gov, 
Thomas.Shader@cookcountyil.gov,  Tangenise.Porter@cookcountyil.gov, 
Tamara.Levickas@cookcountyil.gov,  Samuel.Cory@cookcountyil.gov, 
Ronald.Prohaska@cookcountyil.gov,  Roger.Comer@cookcountyil.gov, 
Robert.Waller@cookcountyil.gov,  Robert. 0'Neiii@cookcountyil.gov, 
Richard.Petersen@cookcountyil.gov,  Rex.Knaperek@cookcountyil.gov, 
Paul.Riley@cookcountyil.gov,  Paul.Huss@cookcountyil.gov, 
Nancy.Pavelka@cookcountyil.gov,  Michael.Quan@cookcountyil.gov, 
Michael.Gomez@cookcountyil.gov,  Michael.Anton@cookcountyil.gov, 
Maurice.Cernick@cookcountyil.gov,  Matthew.Walsh@cookcountyil.gov, 
Alexander.Brodie@cookcountyil.gov,  Lisa.Farinella@cookcountyil.gov, 
Kevin.Graff@cookcountyil.gov,  Kevin.Cooper@cookcountyil.gov, 
Kevin.Christofidis@cookcountyil.gov,  Kelly.Sweeney@cookcountyil.gov, 
Jonathan.Mobley@cookcountyil.gov,  John.Steed@cookcountyil.gov, 
John.Pradun@cookcountyil.gov,  Jeffrey.Pasqua@cookcountyil.gov, 
James.Scannell@cookcountyil.gov,  James.Hughes@cookcountyil.gov, 
Lissette.Rivera@cookcountyil.gov,  Giovanni.Veitkus@cookcountyil.gov, 
Gary.Newsom@cookcountyil.gov,  Frank.Caridei@cookcountyil.gov, 
Felix.Arvelo@cookcountyil.gov,  Diane.Haras@cookcountyil.gov, 
David.Delgado1@cookcountyil.gov,  Daniel.Strong@cookcountyil.gov, 
Daniel.Burke@cookcountyil.gov,  Cedric.Mccloud@cookcountyil.gov, 
Catherine.Domine@cookcountyil.gov,  Anthony.Burns@cookcountyil.gov, 
Gary.Rizzo@cookcountyil.gov,  Luis.Santoyo@cookcountyil.gov, 
Ricardo.Hardy@cookcountyil.gov,  Wanda.Walker@cookcountyil.gov, 
William.Mak@cookcountyil.gov,  Daniel.Moreci@cookcountyil.gov, 
Darren.Makowski@cookcountyil.gov,  Dennis.Nicpan@cookcountyil.gov, 
James.Dillon@cookcountyil.gov,  John.Hammond@cookcountyil.gov, 
Joseph.Giunta@cookcountyil.gov,  Leonard.Jagielski@cookcountyil.gov, 
Miles.Cooperman@cookcountyil.gov,  Patrick.Hecker@cookcountyil.gov, 
Richard.OBrien1@cookcountyil.gov,  Richard.Young2@cookcountyil.gov, 
Joseph.Danzl@cookcountyil.gov,  Zelda.Whittler@cookcountyil.gov,  CCSO  Intel 
(Sheriff) 

June  30,  2020  8:56:06  AM  CDT 
June  30,  2020  8:56:1 1  AM  CDT 


Sent: 

Received: 


Anarchist  Exremists/Criminal  hackers 


From: 

To: 

Sent: 

Received: 


Robert  Lunk  (Sheriff)  <Robert.Lunk@cookcountyil.gov> 

Tarry  Williams  (Sheriff)  <Tarry.Williams@cookcountyil.gov>,  Kathleen 
Urbanczyk  (Sheriff)  <Kathleen. Urbanczyk@cookcountyil.gov> 

June  30,  2020  9:36:07  AM  CDT 
June  30,  2020  9:36:09  AM  CDT 


Attachments:  Anarchist  Extremists  -  Antifa.pdf,  (U--FOUO)  MB  -  Criminal  Hackers  Target  US 

Law  Enforcement  Data  06262020.pdf 


Robert  A.  Lunk 

Investigator  #6236 
Cook  County  Sheriff's  Office 
Cell  (312)  343-4684 
Robert.Lunk@cookccountyii.gov 


THIS  IS  A  CONFIDENTIAL  LAW  ENFORCEMENT  COMMUNICATION  The  contents  of  this  e-mail 
message  and  any  attachments  are  intended  solely  for  the  addressee(s)  named  in  this  message.  This 
communication  is  intended  to  be  and  to  remain  confidential.  If  you  are  not  the  intended  recipient  of  this 
message,  or  if  this  message  has  been  addressed  to  you  in  error,  please  immediately  alert  the  sender  by 
reply-email  and  then  delete  this  message  and  its  attachments.  Do  not  deliver,  distribute,  transmit  or  copy 
this  message  and/or  any  attachments  and  if  you  are  not  the  intended  recipient,  do  not  disclose  the 
contents  or  take  any  action  relative  to  the  information  contained  in  this  communication  and/or 
attachments.  This  e-mail  and  any  attached  documents  may  contain  Law  Enforcement  Sensitive  material 
and  should  not  be  disseminated  outside  of  official  law  enforcement  channels.  The  information  contained 
in  this  message  as  well  as  any  attachments  shall  not  be  released  to  the  media  or  the  general  public. 


Anarchist  Exremists/Criminal  hackers 


From: 


To: 

Sent: 

Received: 

Attachments: 


Robert  Lunk  (Sheriff)  </0=EXCHANGELABS/OU=EXCHANGE  ADMINISTRATIVE 
GROUP 

(FYDIBOHF23SPDLT)/CN=RECIPIENTS/CN=AADABC964D1  E4668A94B0C827FB7CBA0 
-ROBERT  LUNK> 

Tarry  Williams  (Sheriff)  <Tarry.Williams@cookcountyil.gov>,  Kathleen  Urbanczyk  (Sheriff) 
<Kathleen. Urbanczyk@cookcountyil.gov> 

June  30,  2020  9:36:07  AM  CDT 
June  30,  2020  9:36:08  AM  CDT 

Anarchist  Extremists  -  Antifa.pdf,  (U--FOUO)  MB  -  Criminal  Hackers  Target  US  Law 
Enforcement  Data  06262020.pdf 


Robert  A.  Lunk 

Investigator  #6236 

Cook  County  Sheriff's  Office 

Cell  (312)  343-4684 

Robert.  L  unk@cookccountyii  go  v 


THIS  IS  A  CONFIDENTIAL  LAW  ENFORCEMENT  COMMUNICATION  The  contents  of  this  e-mail 
message  and  any  attachments  are  intended  solely  for  the  addressee(s)  named  in  this  message.  This 
communication  is  intended  to  be  and  to  remain  confidential  If  you  are  not  the  intended  recipient  of  this 
message,  or  if  this  message  has  been  addressed  to  you  in  error,  please  immediately  alert  the  sender  by 
reply-email  and  then  delete  this  message  and  its  attachments.  Do  not  deliver,  distribute,  transmit  or  copy 
this  message  and/or  any  attachments  and  if  you  are  not  the  intended  recipient,  do  not  disclose  the 
contents  or  take  any  action  relative  to  the  information  contained  in  this  communication  and/or 
attachments.  This  e-mail  and  any  attached  documents  may  contain  Law  Enforcement  Sensitive  material 
and  should  not  be  disseminated  outside  of  official  law  enforcement  channels.  The  information  contained 
in  this  message  as  well  as  any  attachments  shall  not  be  released  to  the  media  or  the  general  public. 


Anarchist  Exremists/Criminal  hackers 


To: 

Sent: 

Received: 


Tarry  Williams  (Sheriff),  Kathleen  Urbanczyk  (Sheriff) 
June  30,  2020  9:36:07  AM  CDT 
June  30,  2020  9:36:08  AM  CDT 


FW:  (U/LES)  TAM-C  Situation  Report  United  States:  30  June  2020  #2 


From: 

To: 

Sent: 

Received: 

Attachments: 

FYI 


Thomas  Tilton  (Emergency  Management)  <Thomas.Tilton@cookcountyil.gov> 
Michael  Brady  (Sheriff)  <Michael.Brady@cookcountyil.gov>,  Robert  Lunk 
(Sheriff)  <Robert. Lunk@cookcountyil.gov> 

June  30,  2020  12:17:06  PM  CDT 
June  30,  2020  12:17:14  PM  CDT 

TAM-C  Situation  Report  United  States_  30  June  2020  #2.xlsx,  DHS  IG  Report 
on  UAS  June  2020.pdf,  2020_06_30.pdf,  DMWF200630.pdf,  Coronavirus 
Special  OSINT  Report  -  SOR  103-20.pdf 


From:  Ness,  Michael  <michael.ness@hq.dhs.gov> 

Sent:  Tuesday,  June  30,  2020  11:54  AM 

To:  Adrian  Cunningham  (Adrian.Cunningham@fema.dhs.gov);  'Adrianne.Michele@socom.mil';  AITES,  KELLIE  A  CIV 
USAF  ACC  55  SFS/S5AT  <kellie.aites@us.af.mil>;  'Allen_Rothbaum@ios.doi.gov';  Anderson,  Matthew  E  LT  USN 
STRATCOM  J34  (USA)  (matthew.e.anderson5.mil@mail.mil)  <matthew.e.anderson5.mil@mail.mil>;  Distler,  Andrew 
(CTR)  <andrew.distler@associates.hq.dhs.gov>;  MARCUS,  ANDREW  <andrew.marcus@hq.dhs.gov>;  Anna  Castillo 
<anna. castillo. l@us.af.mil>;  Brad  Tippit  (Brad.Tippit@Missouricitytx.gov)  <Brad.Tippit@Missouricitytx.gov>; 
'Bruce.Steven.Miller@us.army.mil';  Pelton,  Bryan  (CTR)  <bryan.pelton@associates.hq.dhs.gov>; 
'captain@berwickpolice.org';  Chandra  White  <Chandra.white@us.af.mil>;  Oppliger,  Christopher 
<christopher.oppliger@hq.dhs.gov>;  Cisneros,  Tony  <Tony.Cisneros@fletc.dhs.gov>;  'CLTibbs@co.pg.md.us'; 
ALFORD,  DALE  <dale.alford@hq.dhs.gov>;  'Darryl_Ward@ios.doi.gov';  ATWOOD,  DAVID  (CTR) 
<david.atwood@associates.hq.dhs.gov>;  Davidson,  Jeffrey  <jeffrey.davidson@hq.dhs.gov>;  Delcore,  Robert 
<Robert.Delcore@uscis.dhs.gov>;  Delgado,  Jose  L  <Jose.Delgado@tsa.dhs.gov>; 

'dennis.gonzalez@CityofRochester.gov';  dgirou@arlingtonva.us;  'dgpeterson@lanl.gov';  Schwarzrock,  Don 
<don.schwarzrock@hq.dhs.gov>;  Downey,  Michael  <Michael.Downey@hq.dhs.gov>;  Dzurilla,  Christopher 
<Christopher.Dzurilla@HQ.DHS.GOV>;  Gagnon,  Bruce  P  <Bruce_Gagnon@nps.gov>;  Graves,  Jeremy  W  MSgt  USAF 
AFDW  (USA)  (jeremy.w.graves.mil@mail.mil)  <jeremy.w.graves.mil@mail.mil>;  greg.brock@nlrb.gov;  HARDING, 
DANIEL  <daniel.harding@hq.dhs.gov>;  Harvey,  Timothy  <Timothy.Harvey@fletc.dhs.gov>;  Henry  Rivero: 
<Henry.Rivero@bep.gov>;  'hhgreen@nmic.navy.mil';  Holder,  Richard  <Richard.Holder@HQ.DHS.GOV>;  Hughes, 
Gregory  (CDC/OPHSS/NCHS)  (nvx2@cdc.gov)  <nvx2@cdc.gov>;  Hunter,  Joseph  David  (Joe)  2d  LT  USAF  (US) 
(joseph.d.hunterl6.mil@mail.mil)  <joseph. d.hunterl6.mil@mail.mil>;  CURRIE,  JASON  (CTR) 

<jason.currie@associates.hq.dhs.gov>;  Jeffrey  McClung  <jeffrey.mcclung@jfcc-imd.stratcom.mil>;  Henderson,  Jesse 
K  CTR  <Jesse.K.Henderson@uscg.mil>;  Tadrick,  Joe  <Joe.Tadrick@hq.dhs.gov>;  John  Bamford 
<Jbamford@arlingtonva.us>;  'john.a.kavaliunas.civ@mail.mil';  'John.Glodo@crystal.dia.mil';  'john.leo-l@nasa.gov'; 
Jonesmcgee,  Darius  A  SSgt  USAF  (USA)  (darius.a.jonesmcgee.mil@mail.mil)  <darius. a.jonesmcgee.mil@mail.mil>;  JS 
Pentagon  DoM  Mailbox  JSSO  Military  Security  Force  <js. pentagon. dom.mbx.jsso-military-security-force@mail.mil>; 
kenneth.j.anderson3.civ@mail.mil;  Kristy  KorchakCampbell  (kristy.korchakcampbell@us.af.mil) 
<kristy.korchakcampbell@us.af.mil>;  kristy.korchak-campbell@auab.afcent.af.mil;  'kunichs@guestservices.com'; 
Battiste,  Lawrence  <lawrence.battiste@hq.dhs.gov>;  Lee  Taylor  (Lee.Taylor@hq.dhs.gov);  Linneman,  Eric 
<Eric.linneman@dla.mil>;  Mannix,  Alan  <Alan.Mannix@bep.gov>;  'mark.holloway@ic.fbi.gov';  Marler,  Christopher  F 
SSgt  USAF  (USA)  (christopher.f.marler.mil@mail.mil)  <christopher.f.marler.mil@mail.mil>;  Mascolo,  John 
<John.Mascolo@tsa.dhs.gov>;  'Matthew.f.croson@usdoj.gov';  McBride,  Chip  <chip.mcbride@hq.dhs.gov>;  Michael 
Malcolm  <michael.s.malcolm2.civ@mail.mil>;  Michael  Robinson:  <michael.robinson@bep.gov>; 
'michael.g.copeland2.civ@mail.mil';  Michael.Kenny@bep.gov;  'michael.w.young8.ctr@mail.mil';  Mike  Evans 
<Mike.Evans@calvertcountymd.gov>;  monika.l.junker.civ@mail.mil;  Moreta,  Richard  <richard.moreta@hq.dhs.gov>; 
Nicholas  Paoletti  (nicholas.paoletti.l@us.af.mil)  <nicholas.paoletti.l@us.af.mil>;  'n-nc.peterson.ncj3.mbx.j34-letic- 
omb@mail.mil';  'Odis.Stroud@cookcountyil.gov';  Oppermann,  George  Henry  CIV  USARMY  USAG  (US) 
<george.h.oppermann.civ@mail.mil>;  Ortega,  John  A  CIV  <John.A.Ortega@uscg.mil>;  Booker,  Patrick  M  (N/A) 
<patrick.m.booker@uscis.dhs.gov>;  Patterson,  Richard  V  (Rick)  CTR  STRATCOM  J34  (US) 
<richard.v.patterson.ctr@mail.mil>;  Pepin,  Andrew  <Andrew.Pepin@HQ.DHS.GOV>;  Groven,  Philip 
<Philip.Groven@hq.dhs.gov>;  Ping,  William  Darion  <william.d.ping.civ@mail.mil>;  Pinkham,  Lawrence  H  JR  CIV 
STRATCOM  J34  (US)  <lawrence.h. pinkham. civ@mail.mil>;  'PittmanT@state.gov';  POULSEN,  ROBERT  A  2d  Lt  USAF 
ACC  55  ISS/IN  <robert.poulsen@us.af.mil>;  'Raymond.Hankins@nlrb.gov';  Loveless,  Richard 


<richard.loveless@hq.dhs.gov>;  Richard  Reed  <Richard.Reed@firstnet.gov>;  Richard  Swarens 
<Richard.Swarens@whmo.mil>;  'Richard.Cestero@bep.gov';  Roddy,  Gene  E.  CIV  WHMO/HQ. 
<Gene.E.Roddy@whmo.mil>;  Russell,  John  W  MSG  USARMY  JS  DOM  (US)  <john.w.russell36.mil@mail.mil>; 
'russell.r.hicks.civ@mail.mil';  BOYER,  RYAN  <ryan.boyer@hq.dhs.gov>;  'Ryan.Gibson@faa.gov'; 
'Salvatore.ingraldi.civ@mail.mil';  Shell,  Alvin  <alvin.shell@bep.gov>;  Sims,  Karen  <karen.sims@hq.doe.gov>; 
'smithbr@state.gov';  Stephen  J  Barbieri  (stephen.j.barbieri@uscis.dhs.gov);  Stephen  Kunich 
<Stephen.Kunich@pae.com>;  'Stephen.Hutchens@bep.gov';  Steven  Schoen  <steven.m.schoen@lmco.com>; 
Stewart,  Kerry  <Kerry.Stewart@cisa.dhs.gov>;  Stewart,  Kevin  L  CTR  <Kevin.L.Stewart@uscg.mil>; 
'sylvia.c.harris.civ@mail.mil';  Thomas  Klug:  <Thomas.Klug@bep.gov>;  'thomas.a.stroud@nasa.gov'; 
'thomas.loyd@uscp.gov';  'Thomas.Tilton@cookcountyil.gov';  Torian,  William  A  Jr  CIV  USAF  (USA) 
(william.a.torian.civ@mail.mil)  <william. a. torian. civ@mail.mil>;  Versichelli,  Thomas 

<thomas.versichelli.civ@mail.mil>;  Victor  Calloway  <vcalloway@gpo.gov>;  Waage,  Timothy  S  CIV  STRATCOM  J34 
(US)  <timothy.s. waage. civ@mail.mil>;  Waterman,  Ronald  T  CIV  DSS  DSS  ISFO  (US) 

<ronald.t.waterman.civ@mail.mil>;  BERG,  WENDY  <wendy.berg@hq.dhs.gov>;  WERNER,  MATTHEW  R  TSgt  USAF 
AFOSI  55  SFS/Det  204  <matthew.werner.4@us.af.mil>;  Wilemon,  Nicole  <nwilemon@blm.gov>;  DeArcangelis, 
William  <william.dearcangelis@HQ.DHS.GOV>;  Balcerzak,  William  J  <William.J.Balcerzak@uscis.dhs.gov>;  Wilson, 
Randall  Craig  CIV  USARMY  21 SIG  BDE  (USA)  (randall.c.wilsonl2.civ@mail.mil)  <randall.c.wilsonl2.civ@mail.mil>; 
Wolf,  Thomas  John  (Tom)  CIV  USARMY  21  SIG  BDE  (US)  (thomas.j.wolf.civ@mail.mil)  <thomas.j.wolf.civ@mail.mil>; 
Wyman,  Isabel  <isabel.wyman@hq.dhs.gov> 

Subject:  FW:  (U/LES)  TAM-C  Situation  Report  United  States:  30  June  2020  #2 


External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 


M  ichcvd/  “Elliot”  New 

Program  Manager 

Industrial  Security  Branch  -  CCIPP  Program  Office 
Office  of  Chief  Security  Officer  |  National  Security  Services  Division 
DHS-HQ  Desk:  202-447-5046  |  Mobile  Work  Cell:  202-853-0569 
Email(s):  michael.ness@hq.dhs.gov,  or  OCSO-SARM@hq.dhs.gov 


Homeland 

Security 


"With  honor  and  integrity,  we  will  safeguard  the  American  people,  our  homeland. 


WARNING:  This  document  is  FOR  OFFICIAL  USE  ONLY  (FOUO).  It  is  to  be  controlled,  stored,  handled,  transmitted,  distributed,  and  disposed  of  in  accordance 
with  DHS  policy  relating  to  FOUO  information.  This  information  shall  not  be  distributed  beyond  the  original  addressees  without  prior  authorization  of  the 
originator.  This  communication,  along  with  any  attachments,  is  covered  by  Federal  and  State  law  governing  electronic  communications  and  may  contain 
restricted  and  legally  privileged  information.  If  the  reader  of  this  message  is  not  the  intended  recipient,  you  are  hereby  notified  that  any  dissemination, 
distribution,  use  or  copying  of  this  message  is  strictly  prohibited.  If  you  have  received  this  in  error,  please  reply  immediately  to  the  sender  and  delete  this 
message. 


From:  McIntyre,  Timothy  A  <Timothv.A.Mclntyre@ice.dhs.gov> 

Sent:  Tuesday,  June  30,  2020  11:08  AM 
To:  Ness,  Michael  <michael.ness@hq.dhs.gov> 

Subject:  (U/LES)  TAM-C  Situation  Report  United  States:  30  June  2020  #2 


Please  see  below  identified  upcoming  events  throughout  the  United  States  in 
connection  to  the  death  of  George  Floyd  in  Minneapolis  on  25  May  2020. 


Region 

City 

Date 

Time 

(Local 

Time) 

Lat 

Lng 

Details 

California 

Sacramento 

7/1/2020 

11 :30LT 

38.576588 

121.493258 

On  1  July 

2020,  at 
11:30LT, 
activists  in 
Sacramento, 

CA  plan  to 
gather  at  the 
California  State 
Capital 

(38.576588,  - 
121.493258). 

California 

San  Jose 

7/2/2020 

14:00LT 

37.337936 

121.884959 

On  2  July 

2020,  at 
14:00LT, 
activists  in  San 
Jose,  CA  plan 
to  gather  at 
the  San  Jose 
City  Hall 
(37.337936,  - 
121.884959) 
and  will  march 
trough 

Highway  101. 

California 

San  Rafael 

7/3/2020 

17:00LT 

37.998162 

122.530775 

On  3  July 

2020,  at 
17:00LT, 
activists  in  San 
Rafael,  Marin 
County,  CA 
plan  to  gather 
at  at  the  Marin 
County  Jail, 
located  at  13 
Peter  Behr 

Drive 

(37.998162,  - 
122.530775). 

California 

Santa  Clara 

7/3/2020 

14:00LT 

37.342293 

121.974469 

On  3  July 

2020,  at 
14:00LT, 
activsts  in 

Santa  Clara, 

CA  plan  to 
gather  at 

Adrian  Wilcox 
High  School 
(37.366277,  - 
121.986160) 
and  will  march 
to  Central  Park 

(37.342293,  - 
121.974469). 

North 

Carolina 

Wilmington 

7/1/2020 

17:00LT 

34.237058 

-77.945888 

On  1  July 

2020,  at 
17:00LT, 
activists  in 
Wilmington,  NC 
plan  to  gather 
at  102  North 

3rd  Street 
(34.237058,  - 
77.945888). 

Pennsylvania 

Allentown 

7/1/2020 

15:30LT 

40.597757 

-75.488056 

On  1  July 

2020,  at 
15:30LT, 
activists  in 
Allentown,  PA 
plan  to  gather 
at  the  corner  of 
15th  Street 
and  Hamilton 
Street 

(40.597757,  - 
75.488056). 

Texas 

Dallas 

7/1/2020 

18:00LT 

32.776428 

-96.797088 

On  1  July 

2020,  at 
18:00LT, 
activists  in 
Dallas,  TX,  will 
stage  a  protest 
in  front  of  the 
City  Hall 
(32.776428,  - 
96.797088). 

Texas 

Denton 

7/1/2020 

14:00LT 

and 

18:00LT 

33.215034 

-97.132987 

On  1  July 

2020,  at 
14:00LT  and 
18:00LT, 
activists  in 
Denton,  TX 
plan  to  hold 
two  protests  at 
Courthouse-on- 
the-Square 
Museum 
(33.215034,  - 
97.132987). 

Virginia 

Fredericksburg 

7/1/2020 

16:00LT 

38.301723 

-77.462895 

On  1  July 

2020,  at 
16:00LT, 
activists  in 
Fredericksburg, 
VA  plan  to 
gather  at 
Hurkamp  Park 

1(38.301723,-  I 
|77.462895).  [ 


TAM-C  Operations 
operations@tamcintel.com 

24/7:  +1.202.922.0068 

https://www.tamc365.com/ 

This  email  transmission  and  any  accompanying  attachments  may  contain  TAM-C 
Solutions  privileged  and  confidential  information  intended  only  for  the  use  of  the 
intended  addressee.  Any  dissemination,  distribution,  copying  or  action  taken  in 
reliance  on  the  contents  of  this  email  by  anyone  other  than  the  intended  recipient  is 
strictly  prohibited.  If  you  have  received  this  email  in  error  please  immediately  delete 
it  and  notify  sender  at  the  above  TAM-C  Solutions  email  address.  Sender  and  TAM-C 
Solutions  accept  no  liability  for  any  damage  caused  directly  or  indirectly  by  receipt  of 
this  email. 


UNCLASSIFIED//FOR  OFFICIAL  USE  ONLY//HSIN  Intelligence  Community 
Distribution _ 


To: 


Sent: 

Received: 

Attachments: 

ALLCON: 


Abraham  Yasin  (Sheriff)  <Abraham.Yasin@cookcountyil.gov>,  Tarry  Williams 
(Sheriff)  <Tarry.Williams@cookcountyil.gov>,  Leo  Schmitz  (Sheriff) 
<Leo.Schmitz@cookcountyil.gov>,  Adriana  Morales  (Sheriff) 
<Adriana.Morales@cookcountyil.gov>,  Alfonzo  Hunter  (Sheriff) 
<Alfonzo.Hunter@cookcountyil.gov>,  Amanda  Gallegos  (Sheriff) 
<Amanda.Gallegos@cookcountyil.gov>,  Amar  Patel  (Sheriff) 
<Amar.Patel@cookcountyil.gov>,  Bradley  Curry  (Sheriff) 
<Bradley.Curry@cookcountyil.gov>,  Brian  White  (Sheriff) 
<Brian.White@cookcountyil.gov>,  Carmen  Gercone  (Sheriff) 
<Carmen.Gercone@cookcountyil.gov>,  Carmen  Ruffin  (Sheriff) 
<Carmen.Ruffin@cookcountyil.gov>,  Christopher  Imhof  (Sheriff) 
<Christopher.lmhof@cookcountyil.gov>,  David  Chiko  (Sheriff) 
<David.Chiko@cookcountyil.gov>,  Erik  Roedel  (Sheriff) 
<Erik.Roedel@cookcountyil.gov>,  Gregory  Ernst  (Sheriff) 
<Gregory.Ernst@cookcountyil.gov>,  Heather  Bock  (Sheriff) 
<Heather.Bock@cookcountyil.gov>,  Jennifer  Black  (Sheriff) 
<Jennifer.Black@cookcountyil.gov>,  Jerry  Baldwin  (Sheriff) 
<Jerry.Baldwin@cookcountyil.gov>,  John  Vega  (Sheriff) 
<John.Vega@cookcountyil.gov>,  John  Webb  (Sheriff) 
<John.Webb@cookcountyil.gov>,  Jonathan  Myslinski  (Sheriff) 
<Jonathan.Myslinski@cookcountyil.gov>,  Joseph  Bellettiere  (Sheriff) 
<Joseph.Bellettiere@cookcountyil.gov>,  Kathleen  Urbanczyk  (Sheriff) 
<Kathleen.Urbanczyk@cookcountyil.gov>,  Kelley  Eldridge  (Sheriff) 
<Kelley.Eldridge@cookcountyil.gov>,  Kevin  Connelly  (Sheriff) 
<Kevin.Connelly@cookcountyil.gov>,  Kevin  Ruel  (Sheriff) 
<Kevin.Ruel@cookcountyil.gov>,  Larry  Schurig  (Sheriff) 
<Larry.Schurig@cookcountyil.gov>,  Lonnie  Hollis  (Sheriff) 
<Lonnie.Hollis@cookcountyil.gov>,  Marlon  Parks  (Sheriff) 
<Marlon.Parks@cookcountyil.gov>,  Matthew  Creen  (Sheriff) 
<Matthew.Creen@cookcountyil.gov>,  Michael  Brady  (Sheriff) 
<Michael.Brady@cookcountyil.gov>,  Michael  Lucente  (Sheriff) 
<Michael.Lucente@cookcountyil.gov>,  Michael  Miller  (Sheriff) 
<Michael.Miller1@cookcountyil.gov>,  Patrick  Dwyer  (Sheriff) 
<Patrick.Dwyer@cookcountyil.gov>,  Patrick  Moerlien  (Sheriff) 
<Patrick.Moerlien@cookcountyil.gov>,  Richard  Brogan  (Sheriff) 
<Richard.Brogan@cookcountyil.gov>,  Richard  O'Brien  (Sheriff) 
<richard.obrien2@cookcountyil.gov>,  Robert  Lunk  (Sheriff) 
<Robert.Lunk@cookcountyil.gov>,  Ronald  Jenkins  (Sheriff) 
<Ronald.Jenkins@cookcountyil.gov>,  Stephen  Bouffard  (Sheriff) 
<Stephen.Bouffard@cookcountyil.gov>,  Theodore  Stajura  (Sheriff) 
<Theodore.Stajura@cookcountyil.gov>,  Jason  Hernandez  (Sheriff) 
<Jason.Hernandez@cookcountyil.gov>,  James  Moore  (Sheriff) 
<James.Moore2@cookcountyil.gov> 

June  30,  2020  4:34:00  PM  CDT 
June  30,  2020  4:33:38  PM  CDT 

SIN06292020  (U)  July  2020  Dates  ofSignificance.pdf,  OSIR-04001-0809- 
20.pdf,  OSIR-04001-0808-20.pdf 


Please  see  attached  latest  intelligence  bulletins  from  the  HSIN  Intelligence  Community. 


Jasmine  Adams 
Criminal  Research  Analyst  II 
Cook  County  Sheriffs  Department 
Strategic  Operations  Center 
3026  S  California  Ave. 


Bids-  5,  2nd  Floor  Rm  205 
Chicaso,  Illinois  60608 


UNCLASSIFIED//FOR  OFFICIAL  USE  ONLY//HSIN  Intelligence  Community 
Distribution _ 


To:  Abraham  Yasin  (Sheriff),  Tarry  Williams  (Sheriff),  Leo  Schmitz  (Sheriff),  Adriana 

Morales  (Sheriff),  Alfonzo  Hunter  (Sheriff),  Amanda  Gallegos  (Sheriff),  Amar  Patel 
(Sheriff),  Bradley  Curry  (Sheriff),  Brian  White  (Sheriff),  Carmen  Gercone  (Sheriff), 
Carmen  Ruffin  (Sheriff),  Christopher  Imhof  (Sheriff),  David  Chiko  (Sheriff),  Erik  Roedel 
(Sheriff),  Gregory  Ernst  (Sheriff),  Heather  Bock  (Sheriff),  Jennifer  Black  (Sheriff),  Jerry 
Baldwin  (Sheriff),  John  Vega  (Sheriff),  John  Webb  (Sheriff),  Jonathan  Myslinski 
(Sheriff),  Joseph  Bellettiere  (Sheriff),  Kathleen  Urbanczyk  (Sheriff),  Kelley  Eldridge 
(Sheriff),  Kevin  Connelly  (Sheriff),  Kevin  Ruel  (Sheriff),  Larry  Schurig  (Sheriff),  Lonnie 
Hollis  (Sheriff),  Marlon  Parks  (Sheriff),  Matthew  Creen  (Sheriff),  Michael  Brady 
(Sheriff),  Michael  Lucente  (Sheriff),  Michael  Miller  (Sheriff),  Patrick  Dwyer  (Sheriff), 
Patrick  Moerlien  (Sheriff),  Richard  Brogan  (Sheriff),  Richard  O'Brien  (Sheriff),  Robert 
Lunk  (Sheriff),  Ronald  Jenkins  (Sheriff),  Stephen  Bouffard  (Sheriff),  Theodore  Stajura 
(Sheriff),  Jason  Hernandez  (Sheriff),  James  Moore  (Sheriff) 

Sent:  June  30,  2020  4:34:00  PM  CDT 

Received:  June  30,  2020  4:33:38  PM  CDT 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

terrence.doran@cookcountyil.gov,  Terrence  Doran  (Sheriff) 
<Terrence.Doran@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,  2020  11:10:03  PM  CDT 

Received: 

June  30,  2020  11:10:09  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


From: 

To: 

Sender: 

Sent: 

Received: 


NW3C  <training@nw3c.org> 

fontella.brown-marshall@cookcountyil.gov,  Fontella  BrownMarshall  (Sheriff) 
<fontella. brownmarshall@cookcountyil.gov> 

NW3C  <members@nw3c.ccsend.com> 

June  30,  2020  11:10:03  PM  CDT 
June  30,  2020  11:10:07  PM  CDT 


External  Message  Disclaimer 


This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 
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June  30,  2020  1 1 :1 0:1 0  PM  CDT 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

dominic.boggia@cookcountyil.gov,  Dominic  Boggia  (Sheriff) 
<Dominic.Boggia@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,  2020  11:10:06  PM  CDT 

Received: 

June  30,  2020  11:10:09  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 
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Dominic  Boggia  (Sheriff) 
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New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

nicholas.bohlsen@cookcountyil.gov,  Nicholas  Bohlsen  (Sheriff) 
<Nicholas.Bohlsen@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,  2020  11:10:07  PM  CDT 

Received: 

June  30,  2020  11:10:10  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 
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New  courses  available! 


From: 

To: 

NW3C  <training@nw3c.org> 
keith.gray@cookcountyil.gov,  Keith  Gray  (Sheriff) 

<Keith.Gray@cookcountyil.gov> 
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Sent: 
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NW3C  <members@nw3c.ccsend.com> 

June  30,  2020  11:10:07  PM  CDT 

June  30,  2020  11:10:12  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 
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New  courses  available! 
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To: 
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<Raymond.Struck@cookcountyil.gov> 
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NW3C  <members@nw3c.ccsend.com> 

June  30,  2020  11:10:07  PM  CDT 

June  30,  2020  11:10:11  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 
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Received: 


Keith  Gray  (Sheriff) 

June  30,  2020  1 1 :1 0:07  PM  CDT 
June  30,  2020  1 1 :1 0:1 2  PM  CDT 
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Raymond  Struck  (Sheriff) 

June  30,  2020  1 1 :1 0:07  PM  CDT 
June  30,  2020  1 1 :1 0:1 2  PM  CDT 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

robert.lobacz@cookcountyil.gov,  Robert  Lobacz  (Sheriff) 
<Robert.Lobacz@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,  2020  11:10:08  PM  CDT 

Received: 

June  30,  2020  11:10:11  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 
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New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

jonathan.janulis@cookcountyil.gov,  Jonathan  Janulis  (Sheriff) 
<Jonathan.Janulis@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,  2020  11:10:08  PM  CDT 

Received: 

June  30,  2020  11:10:13  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 
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From: 

NW3C  <training@nw3c.org> 

To: 

robert.ruminski@cookcountyil.gov,  Robert  Ruminski  (Sheriff) 
<Robert.Ruminski@cookcountyil.gov> 
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NW3C  <members@nw3c.ccsend.com> 

Sent: 
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External  Message  Disclaimer 
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An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 
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Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,2020  11:10:09  PM  CDT 

Received: 

June  30,  2020  11:10:11  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

elliott.reyes@cookcountyil.gov,  Elliott  Reyes  (Sheriff) 

<  El  liott.  Reyes@cookcou  ntyi  1  .gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,2020  11:10:09  PM  CDT 

Received: 

June  30,  2020  11:10:16  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


From: 

To: 

NW3C  <training@nw3c.org> 

katherine.walsh@cookcountyil.gov,  Katherine  Walsh  (Sheriff) 
<Katherine.Walsh@cookcountyil.gov> 

Sender: 

Sent: 

Received: 

NW3C  <members@nw3c.ccsend.com> 

June  30,2020  11:10:09  PM  CDT 

June  30,  2020  11:10:17  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

patrick.donovan@cookcountyil.gov,  Patrick  Donovan  (Sheriff) 
<Patrick.Donovan@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,2020  11:10:09  PM  CDT 

Received: 

June  30,  2020  11:10:15  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


To: 

Sent: 

Received: 


Jimeal  Haddad  (Sheriff) 

June  30,  2020  1 1 :1 0:09  PM  CDT 
June  30,  2020  1 1 :1 0:1 2  PM  CDT 


New  courses  available! 


To: 

Sent: 

Received: 


Elliott  Reyes  (Sheriff) 

June  30,  2020  1 1 :1 0:09  PM  CDT 
June  30,  2020  1 1 :1 0:1 7  PM  CDT 


New  courses  available! 


To: 

Sent: 

Received: 


Katherine  Walsh  (Sheriff) 

June  30,  2020  1 1 :1 0:09  PM  CDT 
June  30,  2020  1 1 :1 0:1 8  PM  CDT 


New  courses  available! 


To: 

Sent: 

Received: 


Patrick  Donovan  (Sheriff) 

June  30,  2020  1 1 :1 0:09  PM  CDT 
June  30,  2020  1 1 :1 0:1 5  PM  CDT 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

sean.gleason@cookcountyil.gov,  Sean  Gleason  (Sheriff) 
<Sean.Gleason@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,  2020  11:10:10  PM  CDT 

Received: 

June  30,  2020  11:10:19  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


From: 

To: 

Sender: 

Sent: 

Received: 


NW3C  <training@nw3c.org> 

fontella.brownmarshall@cookcountyil.gov,  Fontella  BrownMarshall  (Sheriff) 
<fontella. brownmarshall@cookcountyil.gov> 

NW3C  <members@nw3c.ccsend.com> 

June  30,  2020  11:10:11  PM  CDT 
June  30,  2020  11:10:13  PM  CDT 


External  Message  Disclaimer 


This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


To: 

Sent: 

Received: 


Fontella  BrownMarshall  (Sheriff) 
June  30,  2020  11:10:11  PM  CDT 
June  30,  2020  11:10:14  PM  CDT 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

daniel.redican@cookcountyil.gov,  Daniel  Redican  (Sheriff) 
<Daniel.Redican@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,  2020  11:10:14  PM  CDT 

Received: 

June  30,  2020  11:10:18  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

pascal.waller@cookcountyil.gov,  Pascal  Waller  (Sheriff) 
<Pascal.Waller@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,  2020  11:10:14  PM  CDT 

Received: 

June  30,  2020  11:10:18  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

brian.dignan@cookcountyil.gov,  Brian  Dignan  (Sheriff) 
<Brian.Dignan@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,  2020  11:10:14  PM  CDT 

Received: 

June  30,  2020  11:10:18  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


To: 

Sent: 

Received: 


Daniel  Redican  (Sheriff) 

June  30,  2020  11:10:14  PM  CDT 
June  30,  2020  1 1 :1 0:1 9  PM  CDT 


New  courses  available! 


To: 

Sent: 

Received: 


Pascal  Waller  (Sheriff) 

June  30,  2020  11:10:14  PM  CDT 
June  30,  2020  1 1 :1 0:1 8  PM  CDT 


New  courses  available! 


To: 

Sent: 

Received: 


Brian  Dignan  (Sheriff) 

June  30,  2020  11:10:14  PM  CDT 
June  30,  2020  1 1 :1 0:1 8  PM  CDT 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

james.davis@cookcountyil.gov,  James  Davis  (Sheriff) 
<James.Davis@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,2020  11:10:15  PM  CDT 

Received: 

June  30,  2020  11:10:19  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

james.draz@cookcountyil.gov,  James  Draz  (Sheriff) 
<James.Draz@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,2020  11:10:15  PM  CDT 

Received: 

June  30,  2020  11:10:20  PM  CDT 

External  Message  Disclaimer 


This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


From: 

To: 

NW3C  <training@nw3c.org> 
helen.siaj@cookcountyil.gov,  Helen  Siaj  (Sheriff) 

<Helen.Siaj@cookcountyil.gov> 

Sender: 

Sent: 

Received: 

NW3C  <members@nw3c.ccsend.com> 

June  30,2020  11:10:15  PM  CDT 

June  30,  2020  11:10:17  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


To: 

Sent: 

Received: 


James  Davis  (Sheriff) 

June  30,  2020  1 1 :1 0:1 5  PM  CDT 
June  30,  2020  1 1 :1 0:20  PM  CDT 


New  courses  available! 


To: 

Sent: 

Received: 


James  Draz  (Sheriff) 

June  30,  2020  1 1 :1 0:1 5  PM  CDT 
June  30,  2020  1 1 :1 0:20  PM  CDT 


New  courses  available! 


To: 

Sent: 

Received: 


Helen  Siaj  (Sheriff) 

June  30,  2020  1 1 :1 0:1 5  PM  CDT 
June  30,  2020  1 1 :1 0:25  PM  CDT 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

nelson.lewis@cookcountyil.gov,  Nelson  Lewis  (Sheriff) 
<Nelson.Lewis@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,  2020  11:10:17  PM  CDT 

Received: 

June  30,  2020  11:10:19  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


To: 

Sent: 

Received: 


Nelson  Lewis  (Sheriff) 

June  30,  2020  1 1 :1 0:1 7  PM  CDT 
June  30,  2020  1 1 :1 0:20  PM  CDT 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

darryl.ashley@cookcountyil.gov,  Darryl  Ashley  (Sheriff) 
<Darryl.Ashley@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,  2020  11:10:21  PM  CDT 

Received: 

June  30,  2020  11:10:25  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


To: 

Sent: 

Received: 


Darryl  Ashley  (Sheriff) 

June  30,  2020  1 1 :1 0:21  PM  CDT 
June  30,  2020  1 1 :1 0:25  PM  CDT 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

timothy.mcphillips@cookcountyil.gov,  Timothy  McPhillips  (Sheriff) 
<Timothy.Mcphillips@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,  2020  11:10:22  PM  CDT 

Received: 

June  30,  2020  11:10:24  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


To: 

Sent: 

Received: 


Timothy  McPhillips  (Sheriff) 

June  30,  2020  1 1 :1 0:22  PM  CDT 
June  30,  2020  1 1 :1 0:25  PM  CDT 


New  courses  available! 


From: 

To: 

Sender: 

Sent: 

Received: 


NW3C  <training@nw3c.org> 

marguerite.mccluskey@cookcountyil.gov,  Marguerite  McCluskey  (Sheriff) 
<Marguerite. McCluskey@cookcountyil.gov> 

NW3C  <members@nw3c.ccsend.com> 

June  30,  2020  11:10:24  PM  CDT 
June  30,  2020  1 1 :1 0:26  PM  CDT 


External  Message  Disclaimer 


This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


To: 

Sent: 

Received: 


Marguerite  McCluskey  (Sheriff) 
June  30,  2020  1 1 :1 0:24  PM  CDT 
June  30,  2020  1 1 :1 0:27  PM  CDT 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

brandon.ducray@cookcountyil.gov,  Brandon  Ducray  (Sheriff) 
<Brandon.Ducray@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,2020  11:10:25  PM  CDT 

Received: 

June  30,  2020  11:10:28  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

patrick.doyle@cookcountyil.gov,  Patrick  Doyle  (Sheriff) 
<Patrick.Doyle@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,2020  11:10:25  PM  CDT 

Received: 

June  30,  2020  11:10:27  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


To: 

Sent: 

Received: 


Brandon  Ducray  (Sheriff) 

June  30,  2020  1 1 :1 0:25  PM  CDT 
June  30,  2020  1 1 :1 0:28  PM  CDT 


New  courses  available! 


To: 

Sent: 

Received: 


Patrick  Doyle  (Sheriff) 

June  30,  2020  1 1 :1 0:25  PM  CDT 
June  30,  2020  1 1 :1 0:27  PM  CDT 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

john.dziedzic@cookcountyil.gov,  John  Dziedzic  (Sheriff) 
<John.Dziedzic@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,  2020  11:10:26  PM  CDT 

Received: 

June  30,  2020  11:10:29  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


From: 

To: 

NW3C  <training@nw3c.org> 

ronald.sachtleben@cookcountyil.gov,  Ronald  Sachtleben  (Sheriff) 

<Ronald.  Sachtleben@cookcountyil.gov> 

Sender: 

Sent: 

Received: 

NW3C  <members@nw3c.ccsend.com> 

June  30,  2020  11:10:26  PM  CDT 

June  30,  2020  11:10:32  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


To: 

Sent: 

Received: 


John  Dziedzic  (Sheriff) 

June  30,  2020  1 1 :1 0:26  PM  CDT 
June  30,  2020  1 1 :1 0:30  PM  CDT 


New  courses  available! 


To: 

Sent: 

Received: 


Ronald  Sachtleben  (Sheriff),  2020  Criminal  Investigations  Supervisors 
June  30,  2020  1 1 :1 0:26  PM  CDT 
June  30,  2020  1 1 :1 0:32  PM  CDT 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

james.dolehide@cookcountyil.gov,  James  Dolehide  (Sheriff) 
<James.Dolehide@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,2020  11:10:29  PM  CDT 

Received: 

June  30,  2020  11:10:31  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


To: 

Sent: 

Received: 


James  Dolehide  (Sheriff) 

June  30,  2020  1 1 :1 0:29  PM  CDT 
June  30,  2020  1 1 :1 0:33  PM  CDT 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

ginny.georgantas@cookcountyil.gov,  Ginny  Georgantas  (Sheriff) 
<Ginny. Georgantas@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,  2020  11:10:32  PM  CDT 

Received: 

June  30,  2020  11:10:36  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


To: 

Sent: 

Received: 


Ginny  Georgantas  (Sheriff) 

June  30,  2020  1 1 :1 0:32  PM  CDT 
June  30,  2020  1 1 :1 0:37  PM  CDT 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

christopher.dangles@cookcountyil.gov,  Christopher  Dangles  (Sheriff) 
<Christopher.Dangles@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,  2020  11:10:33  PM  CDT 

Received: 

June  30,  2020  11:10:34  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


To: 

Sent: 

Received: 


Christopher  Dangles  (Sheriff) 
June  30,  2020  1 1 :1 0:33  PM  CDT 
June  30,  2020  1 1 :1 0:35  PM  CDT 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

michael.dwyer@cookcountyil.gov,  Michael  Dwyer  (Sheriff) 
<Michael.Dwyer@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,2020  11:10:39  PM  CDT 

Received: 

June  30,  2020  11:10:42  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

robert.hausherr@cookcountyil.gov,  Robert  Hausherr  (Sheriff) 
<Robert.Hausherr@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,  2020  11:10:40  PM  CDT 

Received: 

June  30,  2020  11:10:42  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


To: 

Sent: 

Received: 


Robert  Hausherr  (Sheriff) 

June  30,  2020  1 1 :1 0:40  PM  CDT 
June  30,  2020  1 1 :1 0:43  PM  CDT 


New  courses  available! 


From: 

To: 

NW3C  <training@nw3c.org> 

krzysztof.wantuch@cookcountyil.gov,  Krzysztof  Wantuch  (Sheriff) 

<Krzysztof.  Wantuch@cookcountyil.gov> 

Sender: 

Sent: 

Received: 

NW3C  <members@nw3c.ccsend.com> 

June  30,  2020  11:10:41  PM  CDT 

June  30,  2020  11:10:43  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


To: 

Sent: 

Received: 


Krzysztof  Wantuch  (Sheriff) 

June  30,  2020  1 1 :1 0:41  PM  CDT 
June  30,  2020  1 1 :1 0:44  PM  CDT 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

devlin.gray@cookcountyil.gov,  Devlin  Gray  (Sheriff) 
<Devlin.Gray@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,  2020  11:10:42  PM  CDT 

Received: 

June  30,  2020  11:10:44  PM  CDT 

External  Message  Disclaimer 


This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

steven.zepeda@cookcountyil.gov,  Steven  Zepeda  (Sheriff) 
<Steven.Zepeda@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,  2020  11:10:42  PM  CDT 

Received: 

June  30,  2020  11:10:46  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

richard.garcia2@cookcountyil.gov,  Richard  Garcia  (Sheriff) 
<Richard.Garcia2@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,  2020  11:10:42  PM  CDT 

Received: 

June  30,  2020  11:10:45  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


To: 

Sent: 

Received: 


Devlin  Gray  (Sheriff) 

June  30,  2020  1 1 :1 0:42  PM  CDT 
June  30,  2020  1 1 :1 0:45  PM  CDT 


New  courses  available! 


To: 

Sent: 

Received: 


Steven  Zepeda  (Sheriff) 

June  30,  2020  1 1 :1 0:42  PM  CDT 
June  30,  2020  1 1 :1 0:46  PM  CDT 


New  courses  available! 


To: 

Sent: 

Received: 


Richard  Garcia  (Sheriff) 

June  30,  2020  1 1 :1 0:42  PM  CDT 
June  30,  2020  1 1 :1 0:45  PM  CDT 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

henry.hemphill@cookcountyil.gov,  Henry  Hemphill  (Sheriff) 
<Henry.Hemphill@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,2020  11:10:45  PM  CDT 

Received: 

June  30,  2020  11:10:47  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


To: 

Sent: 

Received: 


Henry  Hemphill  (Sheriff) 

June  30,  2020  1 1 :1 0:45  PM  CDT 
June  30,  2020  1 1 :1 0:48  PM  CDT 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

michael.kizaric@cookcountyil.gov,  Michael  Kizaric  (Sheriff) 
<Michael.Kizaric@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,  2020  11:10:46  PM  CDT 

Received: 

June  30,  2020  11:10:48  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


To: 

Sent: 

Received: 


Michael  Kizaric  (Sheriff) 

June  30,  2020  1 1 :1 0:46  PM  CDT 
June  30,  2020  1 1 :1 0:49  PM  CDT 


New  courses  available! 


From: 

To: 

Sender: 

Sent: 

Received: 


NW3C  <training@nw3c.org> 

marissa.sanchezkrug@cookcountyil.gov,  Marissa  SanchezKrug  (Sheriff) 
<Marissa.SanchezKrug@cookcountyil.gov> 

NW3C  <members@nw3c.ccsend.com> 

June  30,  2020  11:10:49  PM  CDT 
June  30,  2020  1 1 :1 0:52  PM  CDT 


External  Message  Disclaimer 


This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


To: 

Sent: 

Received: 


Marissa  SanchezKrug  (Sheriff) 
June  30,  2020  1 1 :1 0:49  PM  CDT 
June  30,  2020  1 1 :1 0:53  PM  CDT 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

scott.lefko@cookcountyil.gov,  Scott  Lefko  (Sheriff) 
<Scott.Lefko@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,  2020  11:10:51  PM  CDT 

Received: 

June  30,  2020  1 1:10:53  PM  CDT 

External  Message  Disclaimer 


This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

keith.mccarter@cookcountyil.gov,  Keith  McCarter  (Sheriff) 
<Keith.McCarter@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,  2020  11:10:51  PM  CDT 

Received: 

June  30,  2020  11:10:53  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


To: 

Sent: 

Received: 


Keith  McCarter  (Sheriff) 

June  30,  2020  1 1 :1 0:51  PM  CDT 
June  30,  2020  1 1 :1 0:54  PM  CDT 


New  courses  available! 


From: 

NW3C  <training@nw3c.org> 

To: 

sajid.haidari@cookcountyil.gov,  Sajid  Haidari  (Sheriff) 
<Sajid.Haidari@cookcountyil.gov> 

Sender: 

NW3C  <members@nw3c.ccsend.com> 

Sent: 

June  30,  2020  11:10:52  PM  CDT 

Received: 

June  30,  2020  11:10:54  PM  CDT 

External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 


An  Agency’s  Cybersecurity  and  the  Integrity  of  Digital 
Evidence? 

Wed,  Jul  08,  2020  1 :00  PM  Eastern 


Digital  Evidence  in  Criminal  Cases  before  the  U.S.  Courts 
of  Appeal:  Trends  and  Issues  for  Consideration 

Thu,  Jul  09,  2020  1:00  PM  Eastern 


OSINT  Made  Easier:  Using  Babel  Street  to  more 
intelligently  search  PAI  for  situational  awareness  and 
discovery 

Tue,  Jul  14,  2020  1:00  PM  Eastern 


NIST  Study  for  Digital  Expand  Your  Opportunities  with  a 

Forensics  Experts  Professional  Certification 


NIST  is  conducting  a  study  to  measure  how  well 
the  digital  forensics  community  does  their  job.  In 
this  study,  you  will  examine  simulated  digital 
evidence  and  then  answer  questions  that  might 
arise  in  a  real  criminal  investigation.  This  study 
is  will  help  evaluate  the  scientific  foundations  of 
digital  forensic  methods. 


NW3C  certifications  are  designed  for 
professionals  in  law  enforcement  and  the  private 
sector.  Certifications  can  help  you  distinguish 
yourself  professionally,  obtain  the  next  step  in 
your  career,  and  qualify  as  a  skilled  fact  or 
expert  witness.  Get  certified  today  to  expand 
your  opportunities. 


BlueLeaks:  Law  Enforcement  Data  Leak 

Thousands  of  U.S.  police  documents  were  leaked  to  the 
public  in  what’s  being  called  “BlueLeaks."  Due  to  this  breach, 
it  is  recommended  that  law  enforcement  agencies  and 
personnel  take  proper  precautions  found  in  this  investigative 
resource.  Please  login  to  view  the  document  under  OPSEC. 


LEARN 


Please  note:  By  clicking  unsubscribe,  you  will  not  receive  mass  communication  from  NW3C, 
Inc.  You  may  still  receive  important  direct  communication  from  NW3C,  Inc.  related  to: 
service  and  account  changes,  products  or  services  for  which  you  have  registered,  and  site 
cancellation  or  business  termination  information. 


NW3C  |  5000  Nasa  Blvd,  Suite  2400,  Fairmont,  WV  26554 
Unsubscribe  |  Privacy  Policy 


New  courses  available! 


To: 

Sent: 

Received: 


Sajid  Haidari  (Sheriff) 

June  30,  2020  1 1 :1 0:52  PM  CDT 
June  30,  2020  1 1 :1 0:55  PM  CDT 


UNCLASSIFIED//FOR  OFFICIAL  USE  ONLY//HSIN  Intelligence  Community 
Distribution _ 


From: 


To: 


Sent: 

Received: 

Attachments: 

ALLCON: 


Jasmine  Adams  (Sheriff)  <Jasmine.Adams@cookcountyil.gov> 

Abraham  Yasin  (Sheriff)  <Abraham.Yasin@cookcountyil.gov>,  Tarry  Williams 
(Sheriff)  <Tarry.Williams@cookcountyil.gov>,  Leo  Schmitz  (Sheriff) 
<Leo.Schmitz@cookcountyil.gov>,  Adriana  Morales  (Sheriff) 
<Adriana.Morales@cookcountyil.gov>,  Alfonzo  Hunter  (Sheriff) 
<Alfonzo.Hunter@cookcountyil.gov>,  Amanda  Gallegos  (Sheriff) 
<Amanda.Gallegos@cookcountyil.gov>,  Amar  Patel  (Sheriff) 
<Amar.Patel@cookcountyil.gov>,  Bradley  Curry  (Sheriff) 
<Bradley.Curry@cookcountyil.gov>,  Brian  White  (Sheriff) 
<Brian.White@cookcountyil.gov>,  Carmen  Gercone  (Sheriff) 
<Carmen.Gercone@cookcountyil.gov>,  Carmen  Ruffin  (Sheriff) 
<Carmen.Ruffin@cookcountyil.gov>,  Christopher  Imhof  (Sheriff) 
<Christopher.lmhof@cookcountyil.gov>,  David  Chiko  (Sheriff) 
<David.Chiko@cookcountyil.gov>,  Erik  Roedel  (Sheriff) 
<Erik.Roedel@cookcountyil.gov>,  Gregory  Ernst  (Sheriff) 
<Gregory.Ernst@cookcountyil.gov>,  Heather  Bock  (Sheriff) 
<Heather.Bock@cookcountyil.gov>,  Jennifer  Black  (Sheriff) 
<Jennifer.Black@cookcountyil.gov>,  Jerry  Baldwin  (Sheriff) 
<Jerry.Baldwin@cookcountyil.gov>,  John  Vega  (Sheriff) 
<John.Vega@cookcountyil.gov>,  John  Webb  (Sheriff) 
<John.Webb@cookcountyil.gov>,  Jonathan  Myslinski  (Sheriff) 
<Jonathan.Myslinski@cookcountyil.gov>,  Joseph  Bellettiere  (Sheriff) 
<Joseph.Bellettiere@cookcountyil.gov>,  Kathleen  Urbanczyk  (Sheriff) 
<Kathleen.Urbanczyk@cookcountyil.gov>,  Kelley  Eldridge  (Sheriff) 
<Kelley.Eldridge@cookcountyil.gov>,  Kevin  Connelly  (Sheriff) 
<Kevin.Connelly@cookcountyil.gov>,  Kevin  Ruel  (Sheriff) 
<Kevin.Ruel@cookcountyil.gov>,  Larry  Schurig  (Sheriff) 
<Larry.Schurig@cookcountyil.gov>,  Lonnie  Hollis  (Sheriff) 
<Lonnie.Hollis@cookcountyil.gov>,  Marlon  Parks  (Sheriff) 
<Marlon.Parks@cookcountyil.gov>,  Matthew  Creen  (Sheriff) 
<Matthew.Creen@cookcountyil.gov>,  Michael  Brady  (Sheriff) 
<Michael.Brady@cookcountyil.gov>,  Michael  Lucente  (Sheriff) 
<Michael.Lucente@cookcountyil.gov>,  Michael  Miller  (Sheriff) 
<Michael.Miller1@cookcountyil.gov>,  Patrick  Dwyer  (Sheriff) 
<Patrick.Dwyer@cookcountyil.gov>,  Patrick  Moerlien  (Sheriff) 
<Patrick.Moerlien@cookcountyil.gov>,  Richard  Brogan  (Sheriff) 
<Richard.Brogan@cookcountyil.gov>,  Richard  O'Brien  (Sheriff) 
<richard.obrien2@cookcountyil.gov>,  Robert  Lunk  (Sheriff) 
<Robert.Lunk@cookcountyil.gov>,  Ronald  Jenkins  (Sheriff) 
<Ronald.Jenkins@cookcountyil.gov>,  Stephen  Bouffard  (Sheriff) 
<Stephen.Bouffard@cookcountyil.gov>,  Theodore  Stajura  (Sheriff) 
<Theodore.Stajura@cookcountyil.gov>,  Jason  Hernandez  (Sheriff) 
<Jason.Hernandez@cookcountyil.gov>,  James  Moore  (Sheriff) 
<James.Moore2@cookcountyil.gov> 

July  1,  2020  9:45:48  AM  CDT 
July  1,  2020  9:45:49  AM  CDT 

SIN06292020  (U)  July  2020  Dates  ofSignificance.pdf,  OSIR-04001-0809- 
20.pdf,  OSIR-04001-0808-20.pdf 


Please  see  attached  latest  intelligence  bulletins  from  the  HSIN  Intelligence  Community. 


Jasmine  Adams 
Criminal  Research  Analyst  II 
Cook  County  Sheriffs  Department 
Strategic  Operations  Center 


3026  S  California  Ave. 
Bids-  5,  2nd  Floor  Rm  205 
Chicago,  Illinois  60608 


UNCLASSIFIED//FOR  OFFICIAL  USE  ONLY//HSIN  Intelligence  Community 
Distribution _ 


To:  Abraham  Yasin  (Sheriff),  Tarry  Williams  (Sheriff),  Leo  Schmitz  (Sheriff),  Adriana 

Morales  (Sheriff),  Alfonzo  Hunter  (Sheriff),  Amanda  Gallegos  (Sheriff),  Amar  Patel 
(Sheriff),  Bradley  Curry  (Sheriff),  Brian  White  (Sheriff),  Carmen  Gercone  (Sheriff), 
Carmen  Ruffin  (Sheriff),  Christopher  Imhof  (Sheriff),  David  Chiko  (Sheriff),  Erik  Roedel 
(Sheriff),  Gregory  Ernst  (Sheriff),  Heather  Bock  (Sheriff),  Jennifer  Black  (Sheriff),  Jerry 
Baldwin  (Sheriff),  John  Vega  (Sheriff),  John  Webb  (Sheriff),  Jonathan  Myslinski 
(Sheriff),  Joseph  Bellettiere  (Sheriff),  Kathleen  Urbanczyk  (Sheriff),  Kelley  Eldridge 
(Sheriff),  Kevin  Connelly  (Sheriff),  Kevin  Ruel  (Sheriff),  Larry  Schurig  (Sheriff),  Lonnie 
Hollis  (Sheriff),  Marlon  Parks  (Sheriff),  Matthew  Creen  (Sheriff),  Michael  Brady 
(Sheriff),  Michael  Lucente  (Sheriff),  Michael  Miller  (Sheriff),  Patrick  Dwyer  (Sheriff), 
Patrick  Moerlien  (Sheriff),  Richard  Brogan  (Sheriff),  Richard  O'Brien  (Sheriff),  Robert 
Lunk  (Sheriff),  Ronald  Jenkins  (Sheriff),  Stephen  Bouffard  (Sheriff),  Theodore  Stajura 
(Sheriff),  Jason  Hernandez  (Sheriff),  James  Moore  (Sheriff) 

Sent:  July  1 , 2020  9:45:48  AM  CDT 

Received:  July  1 , 2020  9:45:50  AM  CDT 


UNCLASSIFIED//FOR  OFFICIAL  USE  ONLY//HSIN  Intelligence  Community 
Distribution _ 


To:  Abraham  Yasin  (Sheriff),  Tarry  Williams  (Sheriff),  Leo  Schmitz  (Sheriff),  Adriana 

Morales  (Sheriff),  Alfonzo  Hunter  (Sheriff),  Amanda  Gallegos  (Sheriff),  Amar  Patel 
(Sheriff),  Bradley  Curry  (Sheriff),  Brian  White  (Sheriff),  Carmen  Gercone  (Sheriff), 
Carmen  Ruffin  (Sheriff),  Christopher  Imhof  (Sheriff),  David  Chiko  (Sheriff),  Erik  Roedel 
(Sheriff),  Gregory  Ernst  (Sheriff),  Heather  Bock  (Sheriff),  Jennifer  Black  (Sheriff),  Jerry 
Baldwin  (Sheriff),  John  Vega  (Sheriff),  John  Webb  (Sheriff),  Jonathan  Myslinski 
(Sheriff),  Joseph  Bellettiere  (Sheriff),  Kathleen  Urbanczyk  (Sheriff),  Kelley  Eldridge 
(Sheriff),  Kevin  Connelly  (Sheriff),  Kevin  Ruel  (Sheriff),  Larry  Schurig  (Sheriff),  Lonnie 
Hollis  (Sheriff),  Marlon  Parks  (Sheriff),  Matthew  Creen  (Sheriff),  Michael  Brady 
(Sheriff),  Michael  Lucente  (Sheriff),  Michael  Miller  (Sheriff),  Patrick  Dwyer  (Sheriff), 
Patrick  Moerlien  (Sheriff),  Richard  Brogan  (Sheriff),  Richard  O'Brien  (Sheriff),  Robert 
Lunk  (Sheriff),  Ronald  Jenkins  (Sheriff),  Stephen  Bouffard  (Sheriff),  Theodore  Stajura 
(Sheriff),  Jason  Hernandez  (Sheriff),  James  Moore  (Sheriff),  Arunas  Buntinas  (Sheriff) 
Cc:  Bradley  Curry  (Sheriff),  Marlon  Parks  (Sheriff),  Brian  White  (Sheriff),  Arunas  Buntinas 

(Sheriff),  Tarry  Williams  (Sheriff) 

Sent:  July  1 , 2020  9:45:48  AM  CDT 

Received:  July  1 , 2020  9:45:50  AM  CDT 


UNCLASSIFIED//FOR  OFFICIAL  USE  ONLY//HSIN  Intelligence  Community 
Distribution _ 


To:  Abraham  Yasin  (Sheriff),  Tarry  Williams  (Sheriff),  Leo  Schmitz  (Sheriff),  Adriana 

Morales  (Sheriff),  Alfonzo  Hunter  (Sheriff),  Amanda  Gallegos  (Sheriff),  Amar  Patel 
(Sheriff),  Bradley  Curry  (Sheriff),  Brian  White  (Sheriff),  Carmen  Gercone  (Sheriff), 
Carmen  Ruffin  (Sheriff),  Christopher  Imhof  (Sheriff),  David  Chiko  (Sheriff),  Erik  Roedel 
(Sheriff),  Gregory  Ernst  (Sheriff),  Heather  Bock  (Sheriff),  Jennifer  Black  (Sheriff),  Jerry 
Baldwin  (Sheriff),  John  Vega  (Sheriff),  John  Webb  (Sheriff),  Jonathan  Myslinski 
(Sheriff),  Joseph  Bellettiere  (Sheriff),  Kathleen  Urbanczyk  (Sheriff),  Kelley  Eldridge 
(Sheriff),  Kevin  Connelly  (Sheriff),  Kevin  Ruel  (Sheriff),  Larry  Schurig  (Sheriff),  Lonnie 
Hollis  (Sheriff),  Marlon  Parks  (Sheriff),  Matthew  Creen  (Sheriff),  Michael  Brady 
(Sheriff),  Michael  Lucente  (Sheriff),  Michael  Miller  (Sheriff),  Patrick  Dwyer  (Sheriff), 
Patrick  Moerlien  (Sheriff),  Richard  Brogan  (Sheriff),  Richard  O'Brien  (Sheriff),  Robert 
Lunk  (Sheriff),  Ronald  Jenkins  (Sheriff),  Stephen  Bouffard  (Sheriff),  Theodore  Stajura 
(Sheriff),  Jason  Hernandez  (Sheriff),  James  Moore  (Sheriff),  Sheriff  Intel 
Sent:  July  1 , 2020  9:45:48  AM  CDT 

Received:  July  1 , 2020  9:45:50  AM  CDT 


UNCLASSIFIED//FOR  OFFICIAL  USE  ONLY//HSIN  Intelligence  Community 
Distribution _ 


To:  Abraham  Yasin  (Sheriff),  Tarry  Williams  (Sheriff),  Leo  Schmitz  (Sheriff),  Adriana 

Morales  (Sheriff),  Alfonzo  Hunter  (Sheriff),  Amanda  Gallegos  (Sheriff),  Amar  Patel 
(Sheriff),  Bradley  Curry  (Sheriff),  Brian  White  (Sheriff),  Carmen  Gercone  (Sheriff), 
Carmen  Ruffin  (Sheriff),  Christopher  Imhof  (Sheriff),  David  Chiko  (Sheriff),  Erik  Roedel 
(Sheriff),  Gregory  Ernst  (Sheriff),  Heather  Bock  (Sheriff),  Jennifer  Black  (Sheriff),  Jerry 
Baldwin  (Sheriff),  John  Vega  (Sheriff),  John  Webb  (Sheriff),  Jonathan  Myslinski 
(Sheriff),  Joseph  Bellettiere  (Sheriff),  Kathleen  Urbanczyk  (Sheriff),  Kelley  Eldridge 
(Sheriff),  Kevin  Connelly  (Sheriff),  Kevin  Ruel  (Sheriff),  Larry  Schurig  (Sheriff),  Lonnie 
Hollis  (Sheriff),  Marlon  Parks  (Sheriff),  Matthew  Creen  (Sheriff),  Michael  Brady 
(Sheriff),  Michael  Lucente  (Sheriff),  Michael  Miller  (Sheriff),  Patrick  Dwyer  (Sheriff), 
Patrick  Moerlien  (Sheriff),  Richard  Brogan  (Sheriff),  Richard  O'Brien  (Sheriff),  Robert 
Lunk  (Sheriff),  Ronald  Jenkins  (Sheriff),  Stephen  Bouffard  (Sheriff),  Theodore  Stajura 
(Sheriff),  Jason  Hernandez  (Sheriff),  James  Moore  (Sheriff),  Arunas  Buntinas  (Sheriff) 
Sent:  July  1 , 2020  9:45:48  AM  CDT 

Received:  July  1 , 2020  9:45:50  AM  CDT 


UNCLASSIFIED//FOR  OFFICIAL  USE  ONLY//HSIN  Intelligence  Community 
Distribution _ 


To:  Abraham  Yasin  (Sheriff),  Tarry  Williams  (Sheriff),  Leo  Schmitz  (Sheriff),  Adriana 

Morales  (Sheriff),  Alfonzo  Hunter  (Sheriff),  Amanda  Gallegos  (Sheriff),  Amar  Patel 
(Sheriff),  Bradley  Curry  (Sheriff),  Brian  White  (Sheriff),  Carmen  Gercone  (Sheriff), 
Carmen  Ruffin  (Sheriff),  Christopher  Imhof  (Sheriff),  David  Chiko  (Sheriff),  Erik  Roedel 
(Sheriff),  Gregory  Ernst  (Sheriff),  Heather  Bock  (Sheriff),  Jennifer  Black  (Sheriff),  Jerry 
Baldwin  (Sheriff),  John  Vega  (Sheriff),  John  Webb  (Sheriff),  Jonathan  Myslinski 
(Sheriff),  Joseph  Bellettiere  (Sheriff),  Kathleen  Urbanczyk  (Sheriff),  Kelley  Eldridge 
(Sheriff),  Kevin  Connelly  (Sheriff),  Kevin  Ruel  (Sheriff),  Larry  Schurig  (Sheriff),  Lonnie 
Hollis  (Sheriff),  Marlon  Parks  (Sheriff),  Matthew  Creen  (Sheriff),  Michael  Brady 
(Sheriff),  Michael  Lucente  (Sheriff),  Michael  Miller  (Sheriff),  Patrick  Dwyer  (Sheriff), 
Patrick  Moerlien  (Sheriff),  Richard  Brogan  (Sheriff),  Richard  O'Brien  (Sheriff),  Robert 
Lunk  (Sheriff),  Ronald  Jenkins  (Sheriff),  Stephen  Bouffard  (Sheriff),  Theodore  Stajura 
(Sheriff),  Jason  Hernandez  (Sheriff),  James  Moore  (Sheriff),  Michael  Aliperti,  Ben 
Spear 

Sent:  July  1 , 2020  9:45:48  AM  CDT 

Received:  July  1 , 2020  9:45:50  AM  CDT 


UNCLASSIFIED//FOR  OFFICIAL  USE  ONLY//HSIN  Intelligence  Community 
Distribution _ 


To:  Abraham  Yasin  (Sheriff),  Tarry  Williams  (Sheriff),  Leo  Schmitz  (Sheriff),  Adriana 

Morales  (Sheriff),  Alfonzo  Hunter  (Sheriff),  Amanda  Gallegos  (Sheriff),  Amar  Patel 
(Sheriff),  Bradley  Curry  (Sheriff),  Brian  White  (Sheriff),  Carmen  Gercone  (Sheriff), 
Carmen  Ruffin  (Sheriff),  Christopher  Imhof  (Sheriff),  David  Chiko  (Sheriff),  Erik  Roedel 
(Sheriff),  Gregory  Ernst  (Sheriff),  Heather  Bock  (Sheriff),  Jennifer  Black  (Sheriff),  Jerry 
Baldwin  (Sheriff),  John  Vega  (Sheriff),  John  Webb  (Sheriff),  Jonathan  Myslinski 
(Sheriff),  Joseph  Bellettiere  (Sheriff),  Kathleen  Urbanczyk  (Sheriff),  Kelley  Eldridge 
(Sheriff),  Kevin  Connelly  (Sheriff),  Kevin  Ruel  (Sheriff),  Larry  Schurig  (Sheriff),  Lonnie 
Hollis  (Sheriff),  Marlon  Parks  (Sheriff),  Matthew  Creen  (Sheriff),  Michael  Brady 
(Sheriff),  Michael  Lucente  (Sheriff),  Michael  Miller  (Sheriff),  Patrick  Dwyer  (Sheriff), 
Patrick  Moerlien  (Sheriff),  Richard  Brogan  (Sheriff),  Richard  O'Brien  (Sheriff),  Robert 
Lunk  (Sheriff),  Ronald  Jenkins  (Sheriff),  Stephen  Bouffard  (Sheriff),  Theodore  Stajura 
(Sheriff),  Jason  Hernandez  (Sheriff),  James  Moore  (Sheriff),  Sheriff  Intel,  Arunas 
Buntinas  (Sheriff) 

Cc:  Bradley  Curry  (Sheriff),  Marlon  Parks  (Sheriff),  Brian  White  (Sheriff),  Arunas  Buntinas 

(Sheriff),  Tarry  Williams  (Sheriff) 

Sent:  July  1 , 2020  9:45:48  AM  CDT 

Received:  July  1 , 2020  9:45:50  AM  CDT 


UNCLASSIFIED//FOR  OFFICIAL  USE  ONLY//HSIN  Intelligence  Community 
Distribution _ 


From: 


To: 


Sent: 

Received: 

Attachments: 

ALLCON: 


Jasmine  Adams  (Sheriff)  </0=EXCHANGELABS/OU=EXCHANGE  ADMINISTRATIVE 
GROUP 

(FYDIBOHF23SPDLT)/CN=RECIPIENTS/CN=846708BEE1C64CC1ABD023D2F5F7264 
E-JASMINE  ADA> 

Abraham  Yasin  (Sheriff)  <Abraham.Yasin@cookcountyil.gov>,  Tarry  Williams  (Sheriff) 
<Tarry.Williams@cookcountyil.gov>,  Leo  Schmitz  (Sheriff) 
<Leo.Schmitz@cookcountyil.gov>,  Adriana  Morales  (Sheriff) 
<Adriana.Morales@cookcountyil.gov>,  Alfonzo  Hunter  (Sheriff) 
<Alfonzo.Hunter@cookcountyil.gov>,  Amanda  Gallegos  (Sheriff) 
<Amanda.Gallegos@cookcountyil.gov>,  Amar  Patel  (Sheriff) 
<Amar.Patel@cookcountyil.gov>,  Bradley  Curry  (Sheriff) 
<Bradley.Curry@cookcountyil.gov>,  Brian  White  (Sheriff) 
<Brian.White@cookcountyil.gov>,  Carmen  Gercone  (Sheriff) 
<Carmen.Gercone@cookcountyil.gov>,  Carmen  Ruffin  (Sheriff) 
<Carmen.Ruffin@cookcountyil.gov>,  Christopher  Imhof  (Sheriff) 
<ChristopherJmhof@cookcountyil.gov>,  David  Chiko  (Sheriff) 

<David.Chiko@cookcountyil.gov>,  Erik  Roedel  (Sheriff)  <Erik.Roedel@cookcountyil.gov>, 
Gregory  Ernst  (Sheriff)  <Gregory.Ernst@cookcountyil.gov>,  Heather  Bock  (Sheriff) 
<Heather.Bock@cookcountyil.gov>,  Jennifer  Black  (Sheriff) 
<Jennifer.Black@cookcountyil.gov>,  Jerry  Baldwin  (Sheriff) 

<Jerry.Baldwin@cookcountyil.gov>,  John  Vega  (Sheriff)  <John.Vega@cookcountyil.gov>, 
John  Webb  (Sheriff)  <John.Webb@cookcountyil.gov>,  Jonathan  Myslinski  (Sheriff) 
<Jonathan.Myslinski@cookcountyil.gov>,  Joseph  Bellettiere  (Sheriff) 
<Joseph.Bellettiere@cookcountyil.gov>,  Kathleen  Urbanczyk  (Sheriff) 
<Kathleen.Urbanczyk@cookcountyil.gov>,  Kelley  Eldridge  (Sheriff) 
<Kelley.Eldridge@cookcountyil.gov>,  Kevin  Connelly  (Sheriff) 
<Kevin.Connelly@cookcountyil.gov>,  Kevin  Ruel  (Sheriff) 
<Kevin.Ruel@cookcountyil.gov>,  Larry  Schurig  (Sheriff) 
<Larry.Schurig@cookcountyil.gov>,  Lonnie  Hollis  (Sheriff) 
<Lonnie.Hollis@cookcountyil.gov>,  Marlon  Parks  (Sheriff) 
<Marlon.Parks@cookcountyil.gov>,  Matthew  Creen  (Sheriff) 
<Matthew.Creen@cookcountyil.gov>,  Michael  Brady  (Sheriff) 
<Michael.Brady@cookcountyil.gov>,  Michael  Lucente  (Sheriff) 
<Michael.Lucente@cookcountyil.gov>,  Michael  Miller  (Sheriff) 
<Michael.Miller1@cookcountyil.gov>,  Patrick  Dwyer  (Sheriff) 
<Patrick.Dwyer@cookcountyil.gov>,  Patrick  Moerlien  (Sheriff) 
<Patrick.Moerlien@cookcountyil.gov>,  Richard  Brogan  (Sheriff) 
<Richard.Brogan@cookcountyil.gov>,  Richard  O'Brien  (Sheriff) 
<richard.obrien2@cookcountyil.gov>,  Robert  Lunk  (Sheriff) 
<Robert.Lunk@cookcountyil.gov>,  Ronald  Jenkins  (Sheriff) 
<Ronald.Jenkins@cookcountyil.gov>,  Stephen  Bouffard  (Sheriff) 
<Stephen.Bouffard@cookcountyil.gov>,  Theodore  Stajura  (Sheriff) 
<Theodore.Stajura@cookcountyil.gov>,  Jason  Hernandez  (Sheriff) 
<Jason.Hernandez@cookcountyil.gov>,  James  Moore  (Sheriff) 
<James.Moore2@cookcountyil.gov> 

July  1,  2020  9:45:48  AM  CDT 
June  30,  2020  4:36:00  PM  CDT 

SIN06292020  (U)  July  2020  Dates  ofSignificance.pdf,  OSIR-04001-0809-20.pdf,  OSIR- 
04001-0808-20.pdf 


Please  see  attached  latest  intelligence  bulletins  from  the  HSIN  Intelligence  Community. 


Jasmine  Adams 

Criminal  Research  Analyst  II 

Cook  County  Sheriffs  Department 


3026  S  California  Ave. 
Bids-  5,  2nd  Floor  Rm  205 
Chicaso ,  Illinois  60608 


FW:  (U/LES)  TAM-C  Situation  Report  United  States:  1  July  2020  #2 


From: 

To: 

Sent: 

Received: 

Attachments: 


FYI 


Thomas  Tilton  (Emergency  Management)  <Thomas.Tilton@cookcountyil.gov> 
Robert  Lunk  (Sheriff)  <Robert.Lunk@cookcountyil.gov>,  Michael  Brady 
(Sheriff)  <Michael.Brady@cookcountyil.gov> 

July  1,  2020  1:14:20  PM  CDT 
July  1,  2020  1:14:29  PM  CDT 

TAM-C  Situation  Report  United  States_  1  July  2020  #2.xlsx,  PACIC 
CIKR_WPAHFC  JIB  -  ANIMAL  AGRICULTURE  FACILITY  LOCATIONS 
DISCLOSED  ON  INTERACTIVE  WEBSITE.pdf,  2020_07_01.pdf,  (U  FOUO) 
DHS  CSAC  Chemical  Current  News  Report  -  20200701  .pdf,  (U  FOUO)  TSA  IA 
UPFRONT  -  20200630.pdf,  (U  FOUO)  TSA  Surface  Complaince  Analysis 
Network  (SCAN)  06242020  to  07012020  -  20200701  .pdf,  (U)  US  Dept,  of 
Transportation  -  Daily  Open  Source  Reporting  -  20200701.pdf,  DSR  (0391-20) 
1  Jul  20  -  Final.pdf,  MTI  Project  SP0520  (06.07).pdf,  OSINT  20200701  .pdf,  SP 
0520  RB  (06.28). pdf 


From:  Ness,  Michael  <michael.ness@hq.dhs.gov> 

Sent:  Wednesday,  July  01,  2020  1:11  PM 

To:  Adrian  Cunningham  (Adrian. Cunningham@fema. dhs.gov);  'Adrianne.Michele@socom.mir;  AITES,  KELLIE  A  CIV 
USAF  ACC  55  SFS/S5AT  <kellie.aites@us.af.mil>;  'Allen_Rothbaum@ios.doi.gov';  Anderson,  Matthew  E  LT  USN 
STRATCOM  J34  (USA)  (matthew.e.anderson5.mil@mail.mil)  <matthew.e.anderson5.mil@mail.mil>;  Distler,  Andrew 
(CTR)  <andrew.distler@associates.hq.dhs.gov>;  MARCUS,  ANDREW  <andrew.marcus@hq.dhs.gov>;  Anna  Castillo 
<anna. castillo. l@us.af.mil>;  Brad  Tippit  (Brad.Tippit@Missouricitytx.gov)  <Brad.Tippit@Missouricitytx.gov>; 
'Bruce.Steven. Miller@us.army.mil';  Pelton,  Bryan  (CTR)  <bryan.pelton@associates.hq.dhs.gov>; 
'captain@berwickpolice.org';  Chandra  White  <Chandra.white@us.af.mil>;  Oppliger,  Christopher 
<christopher.oppliger@hq.dhs.gov>;  Cisneros,  Tony  <Tony.Cisneros@fletc.dhs.gov>;  'CLTibbs@co.pg.md.us'; 
ALFORD,  DALE  <dale.alford@hq.dhs.gov>;  'Darryl_Ward@ios.doi.gov';  ATWOOD,  DAVID  (CTR) 
<david.atwood@associates.hq.dhs.gov>;  Davidson,  Jeffrey  <jeffrey.davidson@hq.dhs.gov>;  Delcore,  Robert 
<Robert.Delcore@uscis.dhs.gov>;  Delgado,  Jose  L  <Jose.Delgado@tsa.dhs.gov>; 

'dennis.gonzalez@CityofRochester.gov';  dgirou@arlingtonva.us;  'dgpeterson@lanl.gov';  Schwarzrock,  Don 
<don.schwarzrock@hq.dhs.gov>;  Downey,  Michael  <Michael.Downey@hq.dhs.gov>;  Dzurilla,  Christopher 
<Christopher.Dzurilla@HQ.DHS.GOV>;  Gagnon,  Bruce  P  <Bruce_Gagnon@nps.gov>;  Graves,  Jeremy  W  MSgt  USAF 
AFDW  (USA)  (jeremy.w.graves.mil@mail.mil)  <jeremy.w.graves.mil@mail.mil>;  greg.brock@nlrb.gov;  HARDING, 
DANIEL  <daniel.harding@hq.dhs.gov>;  Harvey,  Timothy  <Timothy.Harvey@fletc.dhs.gov>;  Henry  Rivero: 
<Henry.Rivero@bep.gov>;  'hhgreen@nmic.navy.mil';  Holder,  Richard  <Richard.Holder@HQ.DHS.GOV>;  Hughes, 
Gregory  (CDC/OPHSS/NCHS)  (nvx2@cdc.gov)  <nvx2@cdc.gov>;  Hunter,  Joseph  David  (Joe)  2d  LT  USAF  (US) 
(joseph.d.hunterl6.mil@mail.mil)  <joseph.d.hunterl6.mil@mail.mil>;  CURRIE,  JASON  (CTR) 

<jason.currie@associates.hq.dhs.gov>;  Jeffrey  McClung  <jeffrey.mcclung@jfcc-imd.stratcom.mil>;  Henderson,  Jesse 
K  CTR  <Jesse.K.Henderson@uscg.mil>;  Tadrick,  Joe  <Joe.Tadrick@hq.dhs.gov>;  John  Bamford 
<Jbamford@arlingtonva.us>;  'john.a.kavaliunas.civ@mail.mil';  'John.Glodo@crystal.dia.mil';  'john.leo-l@nasa.gov'; 
Jonesmcgee,  Darius  A  SSgt  USAF  (USA)  (darius.a.jonesmcgee.mil@mail.mil)  <darius.a.jonesmcgee.mil@mail.mil>;  JS 
Pentagon  DoM  Mailbox  JSSO  Military  Security  Force  <js. pentagon. dom.mbx.jsso-military-security-force@mail.mil>; 
kenneth.j.anderson3.civ@mail.mil;  Kristy  KorchakCampbell  (kristy.korchakcampbell@us.af.mil) 
<kristy.korchakcampbell@us.af.mil>;  kristy.korchak-campbell@auab.afcent.af.mil;  'kunichs@guestservices.com'; 
Battiste,  Lawrence  <lawrence.battiste@hq.dhs.gov>;  Lee  Taylor  (Lee.Taylor@hq.dhs.gov);  Linneman,  Eric 
<Eric.linneman@dla.mil>;  Mannix,  Alan  <Alan.Mannix@bep.gov>;  'mark.holloway@ic.fbi.gov';  Marler,  Christopher  F 
SSgt  USAF  (USA)  (christopher.f.marler.mil@mail.mil)  <christopher.f.marler.mil@mail.mil>;  Mascolo,  John 
<John.Mascolo@tsa.dhs.gov>;  'Matthew.f.croson@usdoj.gov';  McBride,  Chip  <chip.mcbride@hq.dhs.gov>;  Michael 
Malcolm  <michael.s.malcolm2.civ@mail.mil>;  Michael  Robinson:  <michael.robinson@bep.gov>; 
'michaeLg.copeland2.civ@mail.mil';  Michael.Kenny@bep.gov;  'michael.w.young8. ctr@mail.mil';  Mike  Evans 
<Mike.Evans@calvertcountymd.gov>;  monika.l.junker.civ@mail.mil;  Moreta,  Richard  <richard.moreta@hq.dhs.gov>; 
Nicholas  Paoletti  (nicholas.paoletti.l@us.af.mil)  <nicholas.paoletti.l@us.af.mil>;  'n-nc.peterson.ncj3.mbx.j34-letic- 
omb@mail.mir;  'Odis.Stroud@cookcountyil.gov';  Oppermann,  George  Henry  CIV  USARMY  USAG  (US) 
<george.h.oppermann.civ@mail.mil>;  Ortega,  John  A  CIV  <John.A.Ortega@uscg.mil>;  Booker,  Patrick  M  (N/A) 


<patrick.m.booker@uscis.dhs.gov>;  Patterson,  Richard  V  (Rick)  CTR  STRATCOM  J34  (US) 
<richard.v.patterson.ctr@mail.mil>;  Pepin,  Andrew  <Andrew.Pepin@HQ.DHS.GOV>;  Groven,  Philip 
<Philip.Groven@hq.dhs.gov>;  Ping,  William  Darion  <william.d.ping.civ@mail.mil>;  Pinkham,  Lawrence  H  JR  CIV 
STRATCOM  J34  (US)  <lawrence.h. pinkham. civ@mail.mil>;  'PittmanT@state.gov';  POULSEN,  ROBERT  A  2d  Lt  USAF 
ACC  55  ISS/IN  <robert.poulsen@us.af.mil>;  'Raymond.Hankins@nlrb.gov';  Loveless,  Richard 
<richard.loveless@hq.dhs.gov>;  Richard  Reed  <Richard.Reed@firstnet.gov>;  Richard  Swarens 
<Richard.Swarens@whmo.mil>;  'Richard.Cestero@bep.gov';  Roddy,  Gene  E.  CIV  WHMO/HQ 
<Gene.E.Roddy@whmo.mil>;  Russell,  John  W  MSG  USARMY  JS  DOM  (US)  <john. w.russell36.mil@mail.mil>; 
'russell.r.hicks.civ@rnail.mN';  BOYER,  RYAN  <ryan.boyer@hq.dhs.gov>;  'Ryan.Gibson@faa.gov'; 

'Salvatore. ingraldi.civ@mail. mil';  Shell,  Alvin  <alvin.shell@bep.gov>;  Sims,  Karen  <karen.sims@hq.doe.gov>; 
'smithbr@state.gov';  Stephen  J  Barbieri  (stephen.j.barbieri@uscis.dhs.gov);  Stephen  Kunich 
<Stephen.Kunich@pae.com>;  'Stephen.Hutchens@bep.gov';  Steven  Schoen  <steven. m.schoen@lmco.com>; 
Stewart,  Kerry  <Kerry.Stewart@cisa.dhs.gov>;  Stewart,  Kevin  L  CTR  <Kevin.L.Stewart@uscg.mil>; 

'sylvia. c.harris.civ@mail. mil';  Thomas  Klug:  <Thomas.Klug@bep.gov>;  'thomas.a.stroud@nasa.gov'; 
'thomas.loyd@uscp.gov';  'Thomas.Tilton@cookcountyil.gov';  Torian,  William  A  Jr  CIV  USAF  (USA) 
(william.a.torian.civ@mail.mil)  <william. a. torian. civ@mail.mil>;  Versichelli,  Thomas 

<thomas.versichelli.civ@mail.mil>;  Victor  Calloway  <vcalloway@gpo.gov>;  Waage,  Timothy  S  CIV  STRATCOM  J34 
(US)  <timothy.s. waage. civ@mail.mil>;  Waterman,  Ronald  T  CIV  DSS  DSS  ISFO  (US) 

<ronald.t.waterman.civ@mail.mil>;  BERG,  WENDY  <wendy.berg@hq.dhs.gov>;  WERNER,  MATTHEW  R  TSgt  USAF 
AFOSI  55  SFS/Det  204  <matthew.werner.4@us.af.mil>;  Wilemon,  Nicole  <nwilemon@blm.gov>;  DeArcangelis, 
William  <william.dearcangelis@HQ.DHS.GOV>;  Balcerzak,  William  J  <William.J.Balcerzak@uscis.dhs.gov>;  Wilson, 
Randall  Craig  CIV  USARMY  21 SIG  BDE  (USA)  (randall.c.wilsonl2.civ@mail.mil)  <randall.c.wilsonl2.civ@mail.mil>; 
Wolf,  Thomas  John  (Tom)  CIV  USARMY  21  SIG  BDE  (US)  (thomas.j.wolf.civ@mail.mil)  <thomas.j.wolf.civ@mail.mil>; 
Wyman,  Isabel  <isabel.wyman@hq.dhs.gov> 

Subject:  FW:  (U/LES)  TAM-C  Situation  Report  United  States:  1  July  2020  #2 


External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 


M  ichaeX/  “EUlot”  blew 

Program  Manager 

Industrial  Security  Branch  -  CCIPP  Program  Office 
Office  of  Chief  Security  Officer  |  National  Security  Services  Division 
DHS-HQ  Desk:  202-447-5046  |  Mobile  Work  Cell:  202-853-0569 
Email(s):  michael.ness@hq.dhs.gov,  or  OCSO-SARM@hq.dhs.gov 


Homeland 

Security 


"With  honor  and  integrity,  we  will  safeguard  the  American  people,  our  homeland,  and  our  values. " 


WARNING:  This  document  is  FOR  OFFICIAL  USE  ONLY  (FOUO).  It  is  to  be  controlled,  stored,  handled,  transmitted,  distributed,  and  disposed  of  in  accordance 
with  DHS  policy  relating  to  FOUO  information.  This  information  shall  not  be  distributed  beyond  the  original  addressees  without  prior  authorization  of  the 
originator.  This  communication,  along  with  any  attachments,  is  covered  by  Federal  and  State  law  governing  electronic  communications  and  may  contain 
restricted  and  legally  privileged  information.  If  the  reader  of  this  message  is  not  the  intended  recipient,  you  are  hereby  notified  that  any  dissemination, 
distribution,  use  or  copying  of  this  message  is  strictly  prohibited.  If  you  have  received  this  in  error,  please  reply  immediately  to  the  sender  and  delete  this 
message. 


From:  McIntyre,  Timothy  A  <Timothv.A.Mclntyre@ice.dhs.gov> 

Sent:  Wednesday,  July  1,  2020  11:42  AM 
To:  Ness,  Michael  <michael.ness@hq.dhs.gov> 

Subject:  (U/LES)  TAM-C  Situation  Report  United  States:  1  July  2020  #2 


Please  see  below  identified  upcoming  events  throughout  the  United  States  in 
connection  to  the  death  of  George  Floyd  in  Minneapolis  on  25  May  2020. 


Region 

City 

Date 

Time 

(Local 

Time) 

Lat 

Lng 

Details 

California 

Alameda 

7/3/2020 

10:00LT 

and 

17:00LT 

37.767066 

122.242998 

On  3  July 

2020,  at 
10:00LT  and 
17:00LT, 
activists  in 
Alameda,  CA, 
will  stage  a 
die  in  protest 
in  front  of  the 
Alameda 
police  station 
at  1555  Oak 

St 

(37.767066,  - 
122.242998). 

Georgia 

Atlanta 

7/2/2020 

17:30 

LT 

33.740149 

-84.345412 

On  2  July 

2020,  at 

17:30  LT, 
activists  in 
Atlanta,  GA, 
intend  to 
protest  at  the 
intersection 
of  Flat  Shoals 
and 

Glenwood 
Avenues 
(33.740149,  - 
84.345412). 

Indiana 

Decatur 

7/3/2020 

18:30LT 

40.829509 

-84.929288 

On  3  July 

2020,  at 
18:30LT, 
activists  in 
Decatur,  IN, 
will  stage  a 
protest  in  618 
W  Madison  St 
(40.829509,  - 
84.929288). 

Indiana 

South 

Bend 

7/2/2020 

11:30 

LT 

41.683323 

-86.250128 

On  2  July 

2020,  at 

11:30  LT, 
activists  in 
South  Bend, 
IN,  plan  to 
protest 
outside  of  the 

Memorial 
Hospital, 
located  at 

602  S 

Michigan 

Street 

(41.683323,  - 
86.250128). 

Maine 

Bath 

7/2/2020 

17:00 

LT 

43.912807 

-69.813777 

On  2  July 

2020,  at 

17:00  LT, 
activists  in 
Bath,  ME, 
intend  to 
protest 
outside  of 

City  Hall 
(43.912807,  - 
69.813777). 

Massachusetts 

Jamaica 

Plain 

7/2/2020 

17:30 

LT 

42.313781 

-71.11474 

On  2  July 

2020,  at 

17:30  LT, 
activists  in 
Jamaica  Plain, 
MA  plan  to 
protest 
outside  of  the 
First  Baptist 
Church  in 
Jamaica  Plain, 
located  at 

633  Centre 
Street 

(42.313781,  - 
71.114740). 

New  York 

Brooklyn 

7/3/2020 

19:00LT 

40.673888 

-73.969678 

On  3  July 

2020,  at 
19:00LT, 
activists  in 
Brooklyn,  NY, 
will  stage  a 
protest  at  the 
Grand  Army 
Plaza 

(40.673888,  - 
73.969678). 

New  York 

New 

Rochelle 

7/3/2020 

16:00LT 

40.929425 

-73.793772 

On  3  july 

2020,  at 
16:00LT, 
activists  in 

New  Rochelle, 
NY,  will  hold 
a  march  from 
the  New 
Rochelle  High 
School 

(40.929425,  - 
73.793772) 
to  Quaker 
Ridge  Rd 
(40.947389,  - 
73.795969). 

North  Carolina 

Wilmington 

7/2/2020 

17:00LT 

34.237058 

-77.945888 

On  2  July 

2020,  at 
17:00LT, 
activists  in 
Wilmington, 
NC,  plan  to 
gather  at  102 
North  3rd 
Street 

(34.237058,  - 
77.945888). 

North  Carolina 

Wilmington 

7/3/2020 

17:00LT 

34.237058 

-77.945888 

On  3  July 

2020,  at 
17:00LT, 
activists  in 
Wilmington, 
NC,  plan  to 
gather  at  102 
North  3rd 
Street 

(34.237058,  - 
77.945888). 

Oklahoma 

Oklahoma 

City 

7/2/2020 

09:00 

LT 

35.469493 

-97.515184 

On  2  July 

2020,  at 

09:00  LT, 
activists  in 
Oklahoma 

City,  OK, 
intend  to 
protest  in 

Kerr  Park 
(35.469493,  - 
97.515184). 

Oregon 

Oak  Grove 

7/2/2020 

17:00 

LT 

45.415813 

122.631741 

On  2  July 

2020,  at 

17:00  LT, 
activists  in 

Oak  Grove, 

OR,  intend  to 
protest  at  the 
intersection 
of  Oak  Grove 
Boulevard 
and 

McLoughlin 
Boulevard 
(45.415813,  - 
122.631741). 

Oregon 

Portland 

7/2/2020 

12:00LT 

45.569932 

- 

On  2  July 

122.687374 

2020,  at 
12:00LT, 
activists  in 
Portland,  OR, 
plan  to  gather 
at  in  the 
corner  of  N 
Rosa  Parks 
Ways  and  N 
Denver 

Avenue 
(45.569932,  - 
122.687374). 

Oregon 

Portland 

7/3/2020 

12:00LT 

45.569932 

122.687374 

On  3  July 

2020,  at 
12:00LT, 
activists  in 
Portland,  OR, 
plan  to  gather 
at  in  the 
corner  of  N 
Rosa  Parks 
Ways  and  N 
Denver 

Avenue 
(45.569932,  - 
122.687374). 

Pennsylvania 

Allentown 

7/2/2020 

15:30 

LT 

40.597724 

-75.488029 

On  2  July 

2020,  at 

15:30  LT, 
activists  in 
Allentown, 

PA,  intend  to 
gather  at  the 
intersection 
of  15th  Street 
and  Hamilton 
Street 

(40.597724,  - 
75.488029). 

Rhode  Island 

West 

Warwick 

7/2/2020 

16:30 

LT 

41.707184 

-71.515405 

On  2  July 

2020,  at 

16:30  LT, 
activists  in 
West 

Warwick,  RI, 
will  hold  a 
protest  at 

100  Factory 
Street 

(41.707184,  - 
71.515405). 

Texas 

Dallas 

7/2/2020 

18:00LT 

32.776428 

-96.797088 

On  2  July 

2020,  at 
18:00LT, 
activists  in 

Dallas,  TX, 
will  stage  a 
protest  in 
front  of  the 
City  Hall 
(32.776428,  - 
96.797088). 

Texas 

Dallas 

7/3/2020 

18:00LT 

32.776428 

-96.797088 

On  3  July 

2020,  at 
18:00LT, 
activists  in 
Dallas,  TX, 
will  stage  a 
protest  in 
front  of  the 
City  Hall 
(32.776428,  - 
96.797088). 

Texas 

Denton 

7/2/2020 

14:00LT 

and 

18:00LT 

33.215034 

-97.132987 

On  2  July 

2020,  at 
14:00LT  and 
18:00LT, 
activists  in 
Denton,  TX, 
plan  to  hold 
two  protests 
at 

Courthouse- 

on-the- 

Square 

Museum 

(33.215034,  - 

97.132987). 

Texas 

Denton 

7/3/2020 

14:00LT 

and 

18:00LT 

33.215034 

-97.132987 

On  3  July 

2020,  at 
14:00LT  and 
18:00LT, 
activists  in 
Denton,  TX, 
plan  to  hold 
two  protests 
at 

Courthouse- 

on-the- 

Square 

Museum 

(33.215034,  - 

97.132987). 

Washington 

Tacoma 

7/2/2020 

17:00 

LT 

47.224418 

122.472874 

On  2  July 

2020,  at 

17:00  LT, 
activists  in 
Tacoma,  WA, 
intend  to 
protest  in 
front  of  the 

Tacoma 

Police 

Department's 
headquarters, 
located  at 

3701  S  Pine 
Street 

(47.224418,  - 
122.472874). 

Wyoming 

Cheyenne 

7/3/2020 

17:00LT 

41.140277 

104.820354 

On  3  July 

2020,  at 
17:00LT, 
activists  in 
Cheyenne, 

WY,  will  stage 
a  protest  in 
front  of  the 
Wyoming 

State  Capitol 
Building 
(41.140277,  - 
104.820354). 

TAM-C  Operations 
operations@tamcintel.com 

24/7:  +1.202.922.0068 

https://www.tamc365.com/ 

This  email  transmission  and  any  accompanying  attachments  may  contain  TAM-C 
Solutions  privileged  and  confidential  information  intended  only  for  the  use  of  the 
intended  addressee.  Any  dissemination,  distribution,  copying  or  action  taken  in 
reliance  on  the  contents  of  this  email  by  anyone  other  than  the  intended  recipient  is 
strictly  prohibited.  If  you  have  received  this  email  in  error  please  immediately  delete 
it  and  notify  sender  at  the  above  TAM-C  Solutions  email  address.  Sender  and  TAM-C 
Solutions  accept  no  liability  for  any  damage  caused  directly  or  indirectly  by  receipt  of 
this  email. 


FW:  (U/LES)  TAM-C  Situation  Report  United  States:  1  July  2020  #2 _ 

To:  Robert  Lunk  (Sheriff),  Michael  Brady  (Sheriff),  Abraham  Yasin  (Sheriff),  Tarry  Williams 

(Sheriff),  Leo  Schmitz  (Sheriff),  Adriana  Morales  (Sheriff),  Alfonzo  Hunter  (Sheriff), 
Amanda  Gallegos  (Sheriff),  Amar  Patel  (Sheriff),  Bradley  Curry  (Sheriff),  Brian  White 
(Sheriff),  Carmen  Gercone  (Sheriff),  Carmen  Ruffin  (Sheriff),  Christopher  Imhof 
(Sheriff),  David  Chiko  (Sheriff),  Erik  Roedel  (Sheriff),  Gregory  Ernst  (Sheriff),  Heather 
Bock  (Sheriff),  Jennifer  Black  (Sheriff),  Jerry  Baldwin  (Sheriff),  John  Vega  (Sheriff), 
John  Webb  (Sheriff),  Jonathan  Myslinski  (Sheriff),  Joseph  Bellettiere  (Sheriff), 

Kathleen  Urbanczyk  (Sheriff),  Kelley  Eldridge  (Sheriff),  Kevin  Connelly  (Sheriff),  Kevin 
Ruel  (Sheriff),  Larry  Schurig  (Sheriff),  Lonnie  Hollis  (Sheriff),  Marlon  Parks  (Sheriff), 
Matthew  Creen  (Sheriff),  Michael  Lucente  (Sheriff),  Michael  Miller  (Sheriff),  Patrick 
Dwyer  (Sheriff),  Patrick  Moerlien  (Sheriff),  Richard  Brogan  (Sheriff),  Richard  O'Brien 
(Sheriff),  Ronald  Jenkins  (Sheriff),  Stephen  Bouffard  (Sheriff),  Theodore  Stajura 
(Sheriff),  Jason  Hernandez  (Sheriff),  James  Moore  (Sheriff) 

Sent:  July  1 , 2020  1 :1 4:20  PM  CDT 

Received:  July  1 , 2020  1 :1 4:31  PM  CDT 


FW:  (U/LES)  TAM-C  Situation  Report  United  States:  1  July  2020  #2 

To:  Robert  Lunk  (Sheriff),  Michael  Brady  (Sheriff) 

Sent:  July  1 , 2020  1 :1 4:20  PM  CDT 

Received:  July  1 , 2020  1 :1 4:29  PM  CDT 


INFO -bomb  1,2, 3, 4 


From: 

To: 

Sent: 

Received: 

Attachments: 


Mike  Grimes  <mgrimes@butlersheriff.org> 

Mike  Grimes  <mgrimes@butlersheriff.org> 

July  2,  2020  12:01 :42  PM  CDT 
July  2,  2020  12:05:47  PM  CDT 

202006-SAB-015.pdf,  2021  Flyer  Final.pdf,  CBRNE  &  Vulnerable  Targets  Bi- 
Monthly  Digest  April  -  May  2020.pdf,  NYPD_Weekly  Terrorism  Brief_26  June 
2020_SHIELD.pdf,  (FOUO)  COVID-19  -  Worldwide  -  Situation  Report  -  07-01- 
20  (Update  109). pdf,  SFIIELD  -  Event  Threat  Assessment  -  2020  Macys  Fourth 
of  July  Fireworks.pdf 


External  Message  Disclaimer 


|  This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 

FYI  and  hope  you  all  have  a  safe  4th  of  July  ! ! 

Here  is  a  link  to  the  CPSC  list  of  overloaded  fireworks:  https://www.cpsc.gov/recalls 
mg 

G  Michael  Grimes 
Bomb  Squad  Commander 
Butler  County  Sheriffs  Office 
705  Hanover  Street 
Hamilton,  OH  45011 

Disp)  513.785.1300 
Off)  513.785.1006 
Fax)  513.785.1220 
Cell)  513.200.6664 


[GovQA]  1  Day  Reminder  -  R0091 42-062920 

From:  Cook  County  Sheriff's  Office  <cookcountysheriff@govqa.us> 

To:  Elizabeth.Scannell@cookcountyil.gov,  Elizabeth  Scannell  (Sheriff) 

<Eliza  beth.Scannell@cookcountyil.gov> 

Sent:  July  3,  2020  8:00:51  AM  CDT 

Received:  July  3,  2020  8:00:55  AM  CDT 


External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 


Reminder  the  following  request  is  due  in  ONE  (1)  business  days:  FOIA  Request  /  R009142-062920 

Please  log  in  to  the  FOIA  Request  Center  to  review  this  request  and  update  as  needed. 

Request  Information 
Assigned  Staff:  Elizabeth  Scannell 
Status:  Received 

Create  Date:  6/29/2020  3:37:05  AM 

Record(s)  Requested:  To  Whom  It  May  Concern:  Pursuant  to  the  Illinois  Freedom  of  Information  Act., 
I  hereby  request  the  following  records:  1.  Documents  mentioning,  describing  or  generated  in  response  to 
the  BlueLeaks  release,  the  preceding  hack  or  subsequent  fallout,  including  but  not  limited  to:  *  Damage 
assessments  *  Emails  *  Interagency  communications  (local,  state,  or  federal)  *  Communications  with 
the  press  about  BlueLeaks  *  Communications  with  Twitter  or  other  social  media  or  sharing  platforms  2. 
Documents  mentioning  or  describing  Distributed  Denial  of  Secrets  (DDoSecrets)  You  may  limit  this 
request  to  records  generated  between  November  1,  2018  and  the  present.  I  am  a  member  of  the  news 
media  and  request  classification  as  such.  I  have  previously  written  about  the  government  and  its 
activities,  with  some  reaching  over  100,000  readers  in  outlets  such  as  Gizmodo,  MuckRock, 
Motherboard,  Property  of  the  People,  Unicorn  Riot,  and  The  Outline,  among  others.  As  such,  as  I  have  a 
reasonable  expectation  of  publication  and  my  editorial  and  writing  skills  are  well  established.  In 
addition,  I  discuss  and  comment  on  the  files  online  and  make  them  available  through  non-profits  such  as 
the  library  Internet  Archive  and  the  journalist  non-profit  MuckRock,  disseminating  them  to  a  large 
audience.  While  my  research  is  not  limited  to  this,  a  great  deal  of  it,  including  this,  focuses  on  the 
activities  and  attitudes  of  the  government  itself.  As  such,  it  is  not  necessary  for  me  to  demonstrate  the 
relevance  of  this  particular  subject  in  advance.  As  my  primary  purpose  is  to  inform  about  government 
activities  by  reporting  on  it  and  making  the  raw  data  available,  I  request  that  fees  be  waived.  The 
requested  documents  will  be  made  available  to  the  general  public,  and  this  request  is  not  being  made  for 
commercial  purposes.  In  the  event  that  there  are  fees,  I  would  be  grateful  if  you  would  inform  me  of  the 
total  charges  in  advance  of  fulfilling  my  request.  I  would  prefer  the  request  filled  electronically,  by  e- 
mail  attachment  if  available  or  CD-ROM  if  not.  Thank  you  in  advance  for  your  anticipated  cooperation 
in  this  matter.  I  look  forward  to  receiving  your  response  to  this  request  within  5  business  days,  as  the 
statute  requires.  Sincerely,  Emma  Best  Upload  documents  directly: 

https://https://www.muckrock.comhttps://accounts.muckrock.com/accounts/login/?next=https%3A%2F 

%2Fwww.muckrock.com%2Faccounts%2Flogin%2F%3Fnext%3D%252Faccounts%252Fagency_login 

%252Fcook-county-sheriff-719%252Fblueleaks-cook-county-sheriff- 

96941%252F%253F&url_auth_token=AAAaaJnszUVssmdgx6fh2R- 

tE3U%3AljppAE%3ADWZbgy7n8640ATjAMxtAsPZltYs 

Login  to  the  system  and  view  this  request  by  clicking  View  the  Request 


This  is  an  auto-generated  email  and  has  originated  from  an  unmonitored  email  account.  Please  DO  NOT  REPLY 


[GovQA]  1  Day  Reminder  -  R0091 42-062920 

To:  Elizabeth  Scannell  (Sheriff) 

Sent:  July  3,  2020  8:00:51  AM  CDT 

Received:  July  3,  2020  8:00:55  AM  CDT 


CSWR-20025  CrowdStrike  Intelligence  Weekly  Report:  Week  of  06/27/2020 

From:  intel-notifications@crowdstrike.com 

To:  keith.morrison@cookcountyil.gov,  Keith  Morrison  (Sheriff) 

<Keith.Morrison@cookcountyil.gov> 

Sent:  July  3,  2020  3:26:37  PM  CDT 

Received:  July  3,  2020  3:26:40  PM  CDT 


External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 


CSWR-20025  CrowdStrike  Intelligence  Weekly  Report:  Week 
of  06/27/2020 

On  22  July  2020,  CrowdStrike  Intelligence  will  host  the  Q2  Executive  Briefing,  an  interactive  session 
that  will  examine  some  of  the  notable  activity  and  trends  observed  during  April,  May,  and  June. 
Briefing  topics  will  include: 

•  Global  Geopolitical  Review 

•  Sector  Threat  Highlight:  Telecommunications 

•  Update  on  Ransomware  and  Data  Leaks 

•  INDRIK  SPIDER:  Post  Indictment  Changes 

•  WICKED  PANDA:  Attribution  Challenges  Posed  with  Cobalt  Strike 


Registration  details  for  the  Q2  Executive  Briefing  will  be  forthcoming  soon. 


eCRIME 


Analysis  Reveals  CARBON  SPIDER  Use  of  REvil;  JSS  Loader  Distribution 
Campaign  Observed 

Multiple  instances  of  REvil  (developed  by  PINCHY  SPIDER)  activity  in  conjunction  with  Cobalt 
Strike  have  been  attributed  with  medium  confidence  by  CrowdStrike  Intelligence  to  CARBON 
SPIDER  (CSA-200830).  The  activity  suggests  the  adversary  is  monetizing  access  to  networks  without 
Point-of-Sale  (PoS)  systems  by  encrypting  them  with  ransomware.  The  assessment  is  based  on 
overlaps  in  tooling,  infrastructure,  and  motivation.  In  particular,  multiple  connections  were  made 
through  Cobalt  Strike  samples  using  the  unique  license  identifier  452436291. 

Separately,  on  29  June  2020,  CrowdStrike  Intelligence  identified  a  Leo  VBS  (CSA-191224) 
distribution  campaign  delivering  JSS  Loader  (CSA-191 197).  While  neither  Leo  VBS  nor  JSS  Loader 
are  unique  to  a  particular  adversary,  it  is  likely  this  campaign  was  conducted  by  CARBON  SPIDER. 
This  assessment  carries  moderate  confidence  based  on  the  combination  of  Tactics,  Techniques,  and 
Procedures  (TTPs)  and  observed  command-and-control  (C2)  infrastructure  (CSA-200844). 

Criminal  Actor  Installs  Pharmaceutical-Themed  Spam  Pages  on  Compromised 
Web  Server 

On  25  June  2020,  CrowdStrike  Falcon  OverWatch  observed  hands-on  activity  conducted  by  a 
criminal  actor  at  a  North  America-based  academic  institution.  The  initial  infection  vector  of  the 
incident  is  unknown,  but  the  hands-on-activity  reveals  interesting  information  about  the  actors  TTPs 
(CSA-200834).  Throughout  25  and  26  June,  the  criminal  actor  performed  reconnaissance  activity  on 
the  host  by  checking  if  their  session  was  being  debugged,  locating  the  web  root,  and  retrieving  user 
account  names.  The  actor  proceeded  to  use  wget  to  retrieve  a  ZIP  archive  from  a  remote  location  and 
decompressed  the  archive  into  the  web  root.  The  ZIP  archive  was  over  500MB  in  size  and  contained 
more  than  30,000  pharmaceutical-themed  web  pages  advertising  various  medications  available  for 
online  purchase  without  a  prescription. 

Reportedly  New  Ransom  X  Ransomware  is  Identified  as  Defray777 

On  26  June  2020,  security  researchers  published  a  report  stating  that  a  new  ransomware  named 
Ransom  Xhad  been  used  in  an  operation  against  a  U.S. -based  government  transportation  department. 
CrowdStrike  Intelligence  has  obtained  and  analyzed  samples  of  the  reportedly  new  ransomware  and 
has  identified  the  family  as  the  existing  Defray777  (CSA-200835). 

Though  security  researchers  use  the  name  Defray777  to  refer  to  this  ransomware,  the  internal  binary 
name  set  at  compile  time — ransom,  exx — led  to  the  name  Ransom  X.  The  new  sample  displays  an 
updated  ransom  note  format.  Previously  observed  Defray777  ransom  notes  included  an  alternate 
contact  method  using  BitMessage;  however,  this  is  no  longer  present  in  the  new  ransom  note.  The 
updated  note  includes  updated  instructions  for  the  victim;  however,  the  instruction  to  “contact 
someone  from  IT  department”  remains  the  same  as  in  previous  ransom  notes. 


New  Ragnar  Locker  Victim  Post  Provides  Insight  to  TTPs;  Indications  of 
Collaborations  Between  BGH  Operators 


A  recent  post  by  VIKING  SPIDER  on  their  dedicated  leak  site  (DLS)  detailing  a  new  victim  has 
provided  insight  to  the  operator’s  TTPs  (CSA-200822).  The  post  alludes  to  the  actors  exploiting 
vulnerabilities  to  secure  initial  access  and  moving  laterally  through  the  network  after  successfully 
elevating  permissions  to  “Domain  admin”  level.  Although  the  exact  vulnerabilities  exploited  are 
unconfirmed,  the  information  provides  important  insights  to  VIKING  SPIDER’s  modus  operandi. 

There  is  increasing  evidence  of  a  collaboration  or  business  relationship  between  VIKING  SPIDER 
and  the  big  game  hunting  (BGH)  operators  TWISTED  SPIDER.  Earlier  in  June,  the  two  adversaries 
hosted  victim  information  from  each  other’s  operations  on  their  DLSs  (CSA-200745).  Both  have 
reiterated  their  intent  to  refrain  from  targeting  healthcare  entities  during  the  current  pandemic,  and 
both  draw  attention  to  their  victims’  security  issues.  This  collaborative  activity  is  unique  in  the  current 
BGH  threat  landscape,  with  Ransomware-as-a-Service  (RaaS)  and  affiliate  programs  the  more 
commonly  observed  business  arrangement. 

Spam  Campaign  Mimicking  Italian  Revenue  Agency  Distributes  Gozi  ISFB 

An  Italian-language  spam  campaign  involving  emails  mimicking  the  Italian  Revenue  Agency  was 
observed  on  29  June  2020  distributing  the  Gozi  ISFB  banking  trojan  (CSA-200842).  The  emails 
included  Excel  4.0  macro  documents,  and  referenced  two  articles  of  Italian  legislation  regarding  tax 
refunds — the  timing  of  the  campaign  was  highly  likely  intended  to  coincide  with  Italy’s  annual  tax 
deadline  of  30  June.  Phishing  campaigns  involving  Excel  4.0  macro  documents  have  become 
increasingly  popular  during  2020  (CSA-200461).  In  contrast  to  typical  macro  documents,  which 
contain  Visual  Basic  for  Applications  (VBA)  macros,  these  documents  use  Excel  4.0  macros  that 
predate  VBA  macros.  It  is  likely  adversaries  are  using  Excel  4.0  macro  documents  to  evade  email  and 
host-based  security  tools  that  are  likely  optimized  to  detect  and  prevent  embedded  VBA  macros. 

DanaBot  Sub-Botnet  4  Distributing  Avaddon  Ransomware 

SCULLY  SPIDER’s  DanaBot  sub-botnet  4  was  observed  by  CrowdStrike  Intelligence  distributing 
Avaddon  ransomware  between  22  and  30  June  2020  (CSA-200846).  This  is  the  first  instance  of  the 
sub-botnet  delivering  this  ransomware  variant — previous  payloads  delivered  by  sub-botnet  4  include 
WIZARD  SPIDER’s  Trickbot,  SMOKY  SPIDER’s  SmokeBot,  and  various  information  stealers  and 
remote  administration  tools  (RATs). 

Avaddon  has  previously  been  distributed  in  spam  campaigns,  including  one  campaign  in  June  2020 
involving  the  Phorpiex  malware  targeting  Japanese  email  addresses  (CSA-200752).  This  Avaddon 
campaign  was  seemingly  opportunistic,  with  no  explicit  sector  or  geographic  focus  identified. 

INDRIK  SPIDER’s  WastedLocker  Continues  to  Grow  Victim  Base;  BGH 
Operators  Continue  to  Add  Victim  Details  to  DLS 

INDRIK  SPIDER  has  continued  to  target  organizations  primarily  in  the  UK  and  North  America  using 
their  new  ransomware  variant  WastedLocker  (CSA-200824).  CrowdStrike  Intelligence  sensitive 
source  reporting  has  confirmed  22  victims  to  date,  with  the  manufacturing  sector  the  most  heavily 
targeted.  Despite  the  naming  of  two  key  members  of  INDRIK  SPIDER  in  unsealed  indictments  and 
others  in  financial  sanctions,  the  group  has  continued  to  show  resilience  in  their  campaigns. 

BitPaymer  operations  have  not  been  observed  since  mid-March  2020,  and  distribution  of  Dridex  was 
last  observed  in  late  March  2020  (CSA-200403).  The  development  and  use  of  WastedLocker  is  likely 
intended  to  distance  INDRIK  SPIDER  from  their  previous  Dridex  and  BitPaymer  operations — though 
similarities  between  BitPaymer  and  WastedLocker  suggest  such  separation  has  not  been  fully 
achieved. 


Alongside  the  identification  of  new  WastedLocker  victims,  several  other  BGH  operators  added  details 
of  their  victims  to  their  associated  DLS  this  week  (see  Figure  1). 


Figure  1.  BGH  Ransomware  Victims  by  Sector  and  Country  (26  June  to  2  July  2020) 


Commodity  Malware  Updates  and  Underground  Forum  Activity;  Stolen  Datasets 
Advertised  for  Sale 

Several  updates,  new  releases,  and  advertisements  were  identified  by  CrowdStrike  Intelligence  within 
the  past  week  on  various  criminal  and  underground  fomms  for  commodity  malware  variants  (see 
summary  in  Table  1). 


DATE 

MALWARE 

DETAILS 

24  June 

2020 

Taurus  Project 

Stealer 

Update  to  newly  released  vl  .4 

•  New  panel  includes  loader  statistics 

•  Filter  added  for  file  grabber  function 

•  Wasabi  and  Daedalus  collection  added 

•  Domain  Detect  redesigned 

24  June 

2020 

Raccoon  Stealer 

Updates  made  to  two  versions: 

•  Minor  fixes  and  improvements  to  v  1.5. 12 

•  Added  Chromium-based  Microsoft  Edge 
browser  support  for  vl.5.13 

•  Bug  fixed  affecting  auto-encryption  in 
vl.5.13 

•  Downtime  planned  between  1  and  4  July 

2020  for  back-end  update 

25  June 

2020 

Buer  Loader 

Updates  for  v  1.3. 7 

•  Runtime  cleaning 

•  Added  a  loader  directory  for  Windows 
Defender  exceptions 

•  Updated  anti-virus 

26  June 

2020 

Avaddon 

Ransomware 

Updates  to  the  build,  including 

•  Minor  improvements  and  bug  fixes 

•  Panel  access  updated 

Ongoing  recruitment  for  “networkers” 

Vendor  urged  customers  to  update  to  the  latest 
version 

26  June 

2020 

Triumph  Loader 

Update  to  vl.2.1 

•  Small  update  to  the  boot-loader 

•  General  improvements  to  the  loader 

29  June 

2020 

Amadey  Loader 

Update  to  v  1.90 

•  Lile  upload  algorithm  redesigned,  and 
number  of  attempts  to  contact  command-and- 
control  (C2)  server  increased  to  5 

•  Loader  will  reattempt  at  later  date  if  target 
server  is  busy 

29  June  2020  Oski  Stealer 

Update  to  vl.9.1,  whereby  helper  DLLs  downloaded 
from  C2  are  now  obfuscated 

Table  1.  Commodity  Malware  Updates  and  Adverts 


Also  identified  by  CrowdStrike  Intelligence  sensitive  sources  are  advertisements  for  various  stolen 
datasets.  These  advertisements  provide  a  snapshot  of  the  type  of  information  available  to  purchase  or 
acquire  from  eCrime  adversaries  that  can  be  used  to  perform  phishing  attacks  or  other  fraudulent 
activity. 

•  A  user  on  an  underground  forum  known  for  database  dumps  and  leaks  recently  shared  a  link  to 
a  dataset  sourced  from  an  Indian  e-commerce  platform.  The  data  included  personally 
identifiable  information  (PII)  and  contact  details,  including  telephone  numbers  and  postal 
addresses. 

•  On  26  June  2020,  an  Iranian  eCrime  actor  advertised  for  sale  the  business  credit  card  details 
for  a  U.S. -based  commercial  real  estate  company.  The  details  were  priced  at  $120  USD. 

•  A  user  with  a  proven  track  record  of  selling  stolen  government  and  academia-related  databases 
advertised  in  June  2020  the  sale  of  a  database  allegedly  sourced  from  the  Saudi  Ministry  of 
Interior.  The  data  includes  passport  details,  user  records,  and  some  travel-related  information. 
The  dataset  is  priced  at  $1,000  USD. 

The  Operators  of  Joker’s  Stash  and  Brian’s  Club  Release  Multiple  Offerings  of 
Compromised  Payment  Card  Information  with  PII 

The  operators  of  Joker’s  Stash  card  shop  released  one  offering  from  their  three  recent  major  breaches 
this  week,  BIGBADABOOM-III-US-part57.  CrowdStrike  Intelligence  expects  the  weekly  release  of 
compromised  payment  card  data  from  the  NEW  WORLD  ORDER,  BIGBADABOOM-III,  and 
NIRVANA  (releases  advertised  as  LOTUS)  breaches  to  continue,  based  on  the  historical  activity  of 
Joker’s  Stash  card  shop.  Additionally,  the  operators  of  Joker’s  Stash  released  four  offerings  of 
compromised  payment  card  data  that  contained  personally  PII  from  the  U.S.,  EU,  and  other 
unspecified  regions  of  the  world.  The  abbreviation  VBV  in  the  offering  highly  likely  indicates  that  it 
contains  additional  information  to  successfully  bypass  or  complete  Verified  by  Visa  (VBV)  fraud 
protection. 


DATE 

RELEASE  NAME 

REGION 

NO.  OF 

CARDS 

27  June  2020 

BIGELEPHANT-LULLINL  O- 

U.S./EU/World 

10,000 

DOB-YBV 

29  June  2020 

PINE  APPLE-FULLINFO- 
DOB-VBV 

U.S./EU/World 

15,000 

30  June  2020 

BEAUTIFULLIFE- 

FULLINFO-DOB-VBV 

U.S./EU/World 

15,000 

1  July  2020 

CULTURALSHOCK- 

FULLINFO-MIX 

U.S./EU/World 

1,000 

1  July  2020 

BIGBADABOOM-III-US- 

part57 

U.S. 

Table  2.  Recent  Joker’s  Stash  Card  Shop  Releases  for  25  June  -  2  July  2020 


From  25  June  to  2  July  2020,  CrowdStrike  Intelligence  sources  observed  the  card  shop  Brian’s  Club 
post  five  releases  of  compromised  payment  card  information  containing  PII  and  included  the 
cardholder’s  date  of  birth  (DOB)  and  Social  Security  number  (SSN). 


DATE 

RELEASE  NAME 

REGION 

PII 

25  June  2020 

0625  U  SIPS  SN 

U.S. 

DOB,  SSN 

26  June  2020 

0626  U  SIPS  SN 

U.S. 

DOB,  SSN 

27  June  2020 

0627  U S  IP  S  SN 

U.S. 

DOB,  SSN 

28  June  2020 

0628  USIPSSN 

U.S. 

DOB,  SSN 

29  June  2020 

0629  U S  IP  S  SN 

U.S. 

DOB,  SSN 

Table  3.  Brian’s  Club  PII  Offerings  for  25  June-  2  July  2020 


TARGETED  INTRUSION 


WICKED  PANDA  Deploys  RouterGod  Malware  in  Targeted  Attacks  Against 
Southeast  Asian  Entities 

As  part  of  ongoing  targeted  activity  against  Southeast  Asian  entities,  CrowdStrike  Falcon  OverWatch 
detected  the  deployment  of  novel  malware,  named  RouterGod,  at  an  entity  associated  with  the 
aviation  industry  in  Hong  Kong.  This  malware  has  likely  been  used  to  target  entities  in  Hong-Kong, 
Macau,  and  Taiwan  with  the  actor  also  deploying  additional  tools  such  as  Cobalt  Strike,  DarkShell, 
and  Proxip  as  part  of  the  same  campaign.  The  Proxip  and  Cobalt  Strike  samples  are  configured  to  use 
subdomains  of  livehost  [ .  ]  live,  a  domain  used  by  WICKED  PANDA  as  part  of  ShadowPad 
activity  targeting  Hong  Kong-based  universities  in  2019  (CSA-200151).  Because  of  the  re-use  of  this 
low  prevalence  domain,  continued  targeting  of  Southeast  Asian  entities  as  well  as  the  deployment  of 
Proxip  and  Cobalt  Strike  in  tandem,  CrowdStrike  Intelligence  currently  attributes  this  activity  to 
WICKED  PANDA  with  high  confidence. 

The  name  RouterGod  is  used  internally  by  the  malware  developers,  likely  due  to  the  ability  of  the 
malware  to  route  encrypted  command  packets  between  infected  hosts.  RouterGod  is  a  .NET 
executable  that  can  be  used  to  execute  arbitrary  scripts  as  well  as  establish  sessions  with  other  infected 
hosts.  Multiple  instances  of  the  malware  can  be  used  in  a  chain  to  deliver  implant  tasking  to  specific 
endpoints  within  victim  networks.  Additional  technical  analysis  is  available  in  CSA-200848. 


Novel  Malware  Families  Loosely  Linked  to  China  Identified 


This  week,  CrowdStrike  Intelligence  released  initial  analytic  findings  on  newly  identified  malware. 
Both  malware  families  were  used  in  operations  consistent  with  Chinese  state-nexus  activity: 

•  In  June  2020,  CrowdStrike  Falcon  OverWatch  observed  an  unknown  adversary  deploy  novel 
malware  as  part  of  an  attempted  compromise  at  a  Southeast  Asian  IT  services  provider.  The 
deployed  malware  uses  a  legitimate  antivirus  product  executable  to  gain  execution  via 
dynamic  link  library  (DLL)  search-order  hijacking  in  order  to  execute  a  malicious  loader  DLL 
that,  in  turn,  decrypts  and  loads  an  associated  payload  file.  Additional  activity  observed 
included  the  execution  of  a  Cobalt  Strike  stager  executable  that  was  used  to  download  an 
additional  payload  as  well  as  PowerShell  commands  used  to  contact  unknown  infrastructure. 
See  CSA-200849  for  more  information. 

•  Also  in  June  2020,  CrowdStrike  Falcon  OverWatch  identified  two  closely  related  incidents  at 
an  East  Asian  multinational  pharmaceutical  company.  Both  instances  featured  a  previously 
unseen  implant  linked  to  activity  CrowdStrike  has  assessed  as  consistent  with  Chinese  state 
interests.  For  this  activity,  legitimate  VirtualBox  executables  were  used  to  host  malicious 
DLLs  that  in  turn  load  and  deobfuscate  the  malicious  payloads.  See  CSA-200833  for  more 
information. 

IMPERIAL  KITTEN  Continues  Operations  Against  Probable  Saudi  Arabian 
Technology  Organizations  with  New  FireBAK  Variant 

CrowdStrike  Intelligence  has  identified  continued  activity  from  the  Iranian  state-nexus  IMPERIAL 
KITTEN  adversary  throughout  the  first  half  of  2020.  The  activity  consisted  of  the  apparent  continued 
development  of  its  FireBAK  implant,  with  new  variants  written  in  PowerShell  and  Visual  Basic  Script 
(VBS).  Additional  deployment  of  the  adversary’s  custom  LaZagne  variant  were  identified  in  late  June 
2020.  Additional  data  suggests  that  current  IMPERIAL  KITTEN  operations  likely  focus  on 
technology-related  organizations  in  Saudi  Arabia.  For  more  information,  see  CSA-200843. 

New  LampCarrier  Cluster  Activity  and  Infrastructure  Identified 

CrowdStrike  Intelligence  has  discovered  previously  unidentified  activity  attributed  to  the  LampCarrier 
cluster  including  Golang-based  malware,  a  Microsoft  Office  document  containing  a  malicious  macro, 
and  previously  unidentified  infrastructure.  Previously  observed  LampCarrier  activity  did  not  include 
malware  as  a  significant  part  of  its  toolset,  as  the  actor  preferred  to  rely  on  living-off-the  land 
techniques.  The  discovery  of  new  malware  and  malicious  documents  indicates  LampCarrier  is 
evolving  its  TTPs,  particularly  in  how  it  establishes  persistence  on  victim  networks.  Additional 
information  and  Indicators  of  Compromise  (IOCs)  are  available  in  CSA-200831. 


HACKTIVISM 


MENA  Hacktivists  Engage  in  Doxxing  and  Defacement  Activity 

On  28  June  2020,  hacktivist  group  Oman  FLackers  claimed  to  have  doxxed  more  than  20  individuals 
they  believe  responsible  for  managing  social  media  accounts  conducting  information  operations 
against  Omani  interests.  The  vast  majority  of  the  purportedly  doxxed  individuals  were  Emirati, 


although  some  citizens  of  other  countries  in  the  Middle  East  and  North  Africa  (MENA)  were  also 
identified.  The  Oman  Hackers  group  claim  to  have  obtained  this  information  by  compromising  a  fake 
account  managed  by  one  of  the  doxxed  individuals  and  then  identifying  additional  accounts  involved 
in  coordinating  inauthentic  behavior.  In  particular,  the  Oman  Hackers  group  focused  its  doxxing 
efforts  on  three  individuals  whom  the  group  believes  to  have  ties  to  various  Emirati  government  and 
security  institutions  as  well  as  some  legal  and  media  organizations.  The  Oman  Hackers  group  is 
currently  highly  active,  continuing  to  claim  that  an  organized  conspiracy  is  harming  the  Omani 
government,  its  regime,  and  the  country's  relations  with  neighboring  countries.  For  more  information, 
see  CSA-200836. 

Throughout  June  2020,  hacktivists  operating  under  the  moniker  Moroccan  Revolution  have  reported 
more  than  1200  notifications  to  the  website  defacement  archive  Zone-H.  While  the  group  has  been 
active  since  at  least  2015,  June  2020  marked  a  significant  increase  in  defacement  claims.  Only  two  of 
the  defacements  listed  in  Zone-H  records  noted  defacements  of  government  websites  in  June,  both  of 
which  were  in  Vietnam.  The  defacement  activity  is  very  likely  opportunistic  in  nature  rather  than 
specifically  targeted,  due  to  the  large  number  of  defacements  with  no  clear  geographic  or  sector 
targeting  theme.  While  CrowdStrike  Intelligence  has  not  independently  attributed  the  geographic 
origins  of  most  members  claiming  association  with  the  group,  Moroccan  Revolution  likely  consists 
broadly  of  North  African  hacktivists  or  individuals  sympathetic  to  issues  in  the  region.  Additional 
information  is  available  in  CSA-200828. 

Fallout  from  BlueLeaks  Release  of  Sensitive  U.S.  Law  Enforcement  Data 

On  19  June  2020,  hacktivist-joumalist  entity  Distributed  Denial  of  Secrets  ( DDOS)  released  269  GB 
of  materials  belonging  to  hundreds  of  law  enforcement  agencies  across  the  U.S.,  naming  the  collection 
BlueLeaks  (CSA-200801).  The  release  coincided  with  protests  against  U.S.  law  enforcement  agencies 
after  the  killing  of  George  FLOYD  on  25  May  and  follows  similar  protests  against  law  enforcement  in 
Latin  America  (LATAM).  Journalist  and  operator  of  DDOS  Emma  BEST — known  to  work  closely 
with  sophisticated  hacktivist  MOLOTOV  JACKAL  and  has  an  established  track  record  of  publishing 
materials  in  the  advancement  of  anti-capitalist  and  other  ideologies  (CSA-200663) — made  an  open 
call  for  breaches  of  U.S.  police  forces,  requesting  that  hacktivists  leak  any  exfiltrated  data  to  DDOS 
(CSA-200697).  BlueLeaks  leveraged  at  least  three  simultaneous  means  of  access  and  distribution:  a 
searchable  web  portal,  a  Tor  mirror  for  the  portal,  and  a  downloadable  Torrent  file  for  the  full 
collection;  recent  leaks  of  sensitive  law  enforcement  data  in  LATAM  were  published  in  a  similar 
manner,  with  a  user-friendly  GUI  enabling  easier  digestion  of  the  data  (CSIT- 19233). 

Among  the  BlueLeaks  data  were  sensitive  documents  belonging  to  the  Maine  Information  and 
Analysis  Center  (MIAC).  Internal  MIAC  communication  was  allegedly  not  compromised  but  results 
of  requests  for  information  (RFIs)  were  exposed,  including  personally  identifiable  information  (PII)  of 
subjects  and  victims  as  well  as  information  regarding  ongoing  investigations  in  Maine.  It  was  also 
revealed  that  MIAC  has  been  closely  tracking  Black  Lives  Matter  (BLM)  events  and  advocacy  groups 
(CSDR-20075). 

Hacktivist  Campaign  Protests  Colombian  Military  Scandal 

On  26  June  2020,  hacktivist  group  Anonymous  Colombia  posted  an  English-language  video 
announcing  a  campaign  to  protest  acts  of  extreme  violence  seven  Colombian  soldiers  committed 
against  indigenous  children.  The  group  claimed  credit  for  a  DDoS  attack  and  website  defacement 
against  two  separate  websites  belonging  to  former  Colombian  president  and  current  Senator  Alvaro 
URIBE.  A  separate  hacktivist  group  known  as  AnonymOus  China  backed  the  campaign,  claiming 
responsibility  for  a  DDoS  attack  of  the  Colombian  Army’s  English  and  Spanish-language  websites. 
This  operation  was  the  second  Anonymous-linked  #OpColombia  campaign  announced  that  week; 


there  has  been  no  observed  overlap  between  the  actors  claiming  the  activities,  highlighting  the 
decentralized  nature  of  the  Anonymous  movement.  For  more  information,  see  CSA-200839. 

Iranian  Hacktivists  Target  Israeli,  U.S.  Based  Entities 

Iranian  hacktivist  group  Death  Squads  claimed  credit  for  a  DDoS  attack  against  the  domains  of  an 
Israeli  domain  registrar  and  a  U.S. -based  bank.  As  the  veracity  and  credibility  of  these  attacks  cannot 
be  confirmed,  the  attack  and  associated  denial  of  service  were  likely  limited  in  duration  and  effect. 
Death  Squads'  latest  claims  represent  a  departure  from  past  efforts  and  are  assessed  to  likely  be 
geopolitically  motivated  due  to  the  group’s  nationalistic  outlook  and  the  backgrounds  of  its  core 
membership.  This  effort  is  likely  of  low  sophistication  and  representative  of  a  singular  hacktivist 
effort  rather  than  part  of  a  wider  campaign.  See  CSA-200837  for  more  information. 

The  timing  of  the  claim  also  coincides  with  additional  (though  apparently  unrelated)  attacks  claimed 
by  Iranian  hacktivist  groups  Vortex  Security  Team  and  Unidentified  Security  Team  against  Israel. 
Specifically,  the  groups  claimed  what  appear  to  be  two  distinct  alleged  intrusions:  one  targeting  an 
Israeli  gas  company’s  server  and  the  other  against  an  unknown  entity.  The  server  is  assessed  to  likely 
have  been  identified  via  exposed  services  or  port-scanning  activity;  the  propensity  of  hacktivists  to 
conflate  publicly  available  information  with  data  breaches  suggests  there  are  even  chances  the  extent 
of  the  intrusion  was  either  exaggerated  or  extremely  limited  in  scale.  The  hacktivist  groups  claim  that 
a  27  June  explosion  near  an  Iranian  military  base  on  24  June  was  a  result  of  an  Israeli  cyberattack,  and 
the  groups  took  retaliatory  action  in  response.  For  further  reading,  see  CSA-200840. 


DATA  EXPOSURE  &  BREACHES 


Threat  Actor  Reportedly  Selling  Data  Stolen  From  14  Companies 

A  threat  actor  is  reportedly  selling  databases  stolen  from  14  different  companies  on  an  underground 
forum,  according  to  media  reports.1  Stolen  data  varies  per  company,  though  all  breaches  reportedly 
include  usernames  and  hashed  passwords.  The  threat  actor  is  selling  the  databases  at  varying  prices, 
ranging  from  $100  to  $1,100  USD.  The  companies  were  all  allegedly  breached  in  2020,  though  the 
exact  dates  of  compromise,  if  true,  remains  unknown.  Of  the  fourteen  companies,  four  companies 
have  previously  reported  breaches.  It  is  currently  unclear  if  the  stolen  databases  from  those  four 
companies  are  connected  to  the  previously  reported  breaches. 

Eight  U.S.  Cities  Reportedly  Impacted  by  Click2Gov  Breaches 

The  local  governments  of  eight  U.S. -based  cities  discovered  a  JavaScript  (JS)  skimmer  had  been 
injected  into  the  payment  portals  of  their  Click2Gov  sites.2  The  eight  cities  were  located  across  three 
U.S.  states.  Industry  researchers  disclosed  two  different  exfiltration  servers  that  hosted  the  JS 
skimmer;  one  server  was  used  for  three  sites  and  one  used  for  the  remaining  five  sites.  The  JS 
skimmer  was  designed  to  collect  payment  card  information,  including  card  number,  expiration  date, 
and  CVY,  as  well  as  names  and  physical  addresses.  Media  reports  speculate  that  these  compromises 
are  the  result  of  a  threat  group  leveraging  Magecart  tactics.  However,  CrowdStrike  Intelligence  does 
not  currently  attribute  this  activity  to  a  known  adversary  at  this  time. 


Recent  Reporting 


CSIT-20100  Analysis  of  TRACER  KITTEN  DNSDAT  Malware  Targeting  the  Middle  Eastern 
Telecommunications  Sector 

This  Tipper  provides  technical  analysis  of  the  DNSDAT  malware  in  use  by  the  Iranian  actor  TRACER 
KITTEN. 

CSMR-20005  CrowdStrike  Intelligence  Monthly  Report  -  May  2020 

This  report  provides  significant  analytic  findings  from  May  2020,  including  trends  observed  in 
targeted  intrusion,  eCrime,  and  hacktivist  operations. 


1  https[:]//www.bleepingcomputer[.]com/news/security/seller-floods-hacker-fomm-with-data-stolen-from- 
14-companies/ 

2  https[:]//blog.trendmicro[.]com/trendlabs-security-intelligence/us-local-govemment-services-targeted- 
by-new-magecart-credit-card-skimming-attack/ 
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CSWR-20025  CrowdStrike  Intelligence  Weekly  Report:  Week 
of  06/27/2020 

On  22  July  2020,  CrowdStrike  Intelligence  will  host  the  Q2  Executive  Briefing,  an  interactive  session 
that  will  examine  some  of  the  notable  activity  and  trends  observed  during  April,  May,  and  June. 
Briefing  topics  will  include: 

•  Global  Geopolitical  Review 

•  Sector  Threat  Highlight:  Telecommunications 

•  Update  on  Ransomware  and  Data  Leaks 

•  INDRIK  SPIDER:  Post  Indictment  Changes 

•  WICKED  PANDA:  Attribution  Challenges  Posed  with  Cobalt  Strike 


Registration  details  for  the  Q2  Executive  Briefing  will  be  forthcoming  soon. 


eCRIME 


Analysis  Reveals  CARBON  SPIDER  Use  of  REvil;  JSS  Loader  Distribution 
Campaign  Observed 

Multiple  instances  of  REvil  (developed  by  PINCHY  SPIDER)  activity  in  conjunction  with  Cobalt 
Strike  have  been  attributed  with  medium  confidence  by  CrowdStrike  Intelligence  to  CARBON 
SPIDER  (CSA-200830).  The  activity  suggests  the  adversary  is  monetizing  access  to  networks  without 
Point-of-Sale  (PoS)  systems  by  encrypting  them  with  ransomware.  The  assessment  is  based  on 
overlaps  in  tooling,  infrastructure,  and  motivation.  In  particular,  multiple  connections  were  made 
through  Cobalt  Strike  samples  using  the  unique  license  identifier  452436291. 

Separately,  on  29  June  2020,  CrowdStrike  Intelligence  identified  a  Leo  VBS  (CSA-191224) 
distribution  campaign  delivering  JSS  Loader  (CSA-191 197).  While  neither  Leo  VBS  nor  JSS  Loader 
are  unique  to  a  particular  adversary,  it  is  likely  this  campaign  was  conducted  by  CARBON  SPIDER. 
This  assessment  carries  moderate  confidence  based  on  the  combination  of  Tactics,  Techniques,  and 
Procedures  (TTPs)  and  observed  command-and-control  (C2)  infrastructure  (CSA-200844). 

Criminal  Actor  Installs  Pharmaceutical-Themed  Spam  Pages  on  Compromised 
Web  Server 

On  25  June  2020,  CrowdStrike  Falcon  OverWatch  observed  hands-on  activity  conducted  by  a 
criminal  actor  at  a  North  America-based  academic  institution.  The  initial  infection  vector  of  the 
incident  is  unknown,  but  the  hands-on-activity  reveals  interesting  information  about  the  actors  TTPs 
(CSA-200834).  Throughout  25  and  26  June,  the  criminal  actor  performed  reconnaissance  activity  on 
the  host  by  checking  if  their  session  was  being  debugged,  locating  the  web  root,  and  retrieving  user 
account  names.  The  actor  proceeded  to  use  wget  to  retrieve  a  ZIP  archive  from  a  remote  location  and 
decompressed  the  archive  into  the  web  root.  The  ZIP  archive  was  over  500MB  in  size  and  contained 
more  than  30,000  pharmaceutical-themed  web  pages  advertising  various  medications  available  for 
online  purchase  without  a  prescription. 

Reportedly  New  Ransom  X  Ransomware  is  Identified  as  Defray777 

On  26  June  2020,  security  researchers  published  a  report  stating  that  a  new  ransomware  named 
Ransom  Xhad  been  used  in  an  operation  against  a  U.S. -based  government  transportation  department. 
CrowdStrike  Intelligence  has  obtained  and  analyzed  samples  of  the  reportedly  new  ransomware  and 
has  identified  the  family  as  the  existing  Defray777  (CSA-200835). 

Though  security  researchers  use  the  name  Defray777  to  refer  to  this  ransomware,  the  internal  binary 
name  set  at  compile  time — ransom,  exx — led  to  the  name  Ransom  X.  The  new  sample  displays  an 
updated  ransom  note  format.  Previously  observed  Defray777  ransom  notes  included  an  alternate 
contact  method  using  BitMessage;  however,  this  is  no  longer  present  in  the  new  ransom  note.  The 
updated  note  includes  updated  instructions  for  the  victim;  however,  the  instruction  to  “contact 
someone  from  IT  department”  remains  the  same  as  in  previous  ransom  notes. 


New  Ragnar  Locker  Victim  Post  Provides  Insight  to  TTPs;  Indications  of 
Collaborations  Between  BGH  Operators 


A  recent  post  by  VIKING  SPIDER  on  their  dedicated  leak  site  (DLS)  detailing  a  new  victim  has 
provided  insight  to  the  operator’s  TTPs  (CSA-200822).  The  post  alludes  to  the  actors  exploiting 
vulnerabilities  to  secure  initial  access  and  moving  laterally  through  the  network  after  successfully 
elevating  permissions  to  “Domain  admin”  level.  Although  the  exact  vulnerabilities  exploited  are 
unconfirmed,  the  information  provides  important  insights  to  VIKING  SPIDER’s  modus  operandi. 

There  is  increasing  evidence  of  a  collaboration  or  business  relationship  between  VIKING  SPIDER 
and  the  big  game  hunting  (BGH)  operators  TWISTED  SPIDER.  Earlier  in  June,  the  two  adversaries 
hosted  victim  information  from  each  other’s  operations  on  their  DLSs  (CSA-200745).  Both  have 
reiterated  their  intent  to  refrain  from  targeting  healthcare  entities  during  the  current  pandemic,  and 
both  draw  attention  to  their  victims’  security  issues.  This  collaborative  activity  is  unique  in  the  current 
BGH  threat  landscape,  with  Ransomware-as-a-Service  (RaaS)  and  affiliate  programs  the  more 
commonly  observed  business  arrangement. 

Spam  Campaign  Mimicking  Italian  Revenue  Agency  Distributes  Gozi  ISFB 

An  Italian-language  spam  campaign  involving  emails  mimicking  the  Italian  Revenue  Agency  was 
observed  on  29  June  2020  distributing  the  Gozi  ISFB  banking  trojan  (CSA-200842).  The  emails 
included  Excel  4.0  macro  documents,  and  referenced  two  articles  of  Italian  legislation  regarding  tax 
refunds — the  timing  of  the  campaign  was  highly  likely  intended  to  coincide  with  Italy’s  annual  tax 
deadline  of  30  June.  Phishing  campaigns  involving  Excel  4.0  macro  documents  have  become 
increasingly  popular  during  2020  (CSA-200461).  In  contrast  to  typical  macro  documents,  which 
contain  Visual  Basic  for  Applications  (VBA)  macros,  these  documents  use  Excel  4.0  macros  that 
predate  VBA  macros.  It  is  likely  adversaries  are  using  Excel  4.0  macro  documents  to  evade  email  and 
host-based  security  tools  that  are  likely  optimized  to  detect  and  prevent  embedded  VBA  macros. 

DanaBot  Sub-Botnet  4  Distributing  Avaddon  Ransomware 

SCULLY  SPIDER’s  DanaBot  sub-botnet  4  was  observed  by  CrowdStrike  Intelligence  distributing 
Avaddon  ransomware  between  22  and  30  June  2020  (CSA-200846).  This  is  the  first  instance  of  the 
sub-botnet  delivering  this  ransomware  variant — previous  payloads  delivered  by  sub-botnet  4  include 
WIZARD  SPIDER’s  Trickbot,  SMOKY  SPIDER’s  SmokeBot,  and  various  information  stealers  and 
remote  administration  tools  (RATs). 

Avaddon  has  previously  been  distributed  in  spam  campaigns,  including  one  campaign  in  June  2020 
involving  the  Phorpiex  malware  targeting  Japanese  email  addresses  (CSA-200752).  This  Avaddon 
campaign  was  seemingly  opportunistic,  with  no  explicit  sector  or  geographic  focus  identified. 

INDRIK  SPIDER’s  WastedLocker  Continues  to  Grow  Victim  Base;  BGH 
Operators  Continue  to  Add  Victim  Details  to  DLS 

INDRIK  SPIDER  has  continued  to  target  organizations  primarily  in  the  UK  and  North  America  using 
their  new  ransomware  variant  WastedLocker  (CSA-200824).  CrowdStrike  Intelligence  sensitive 
source  reporting  has  confirmed  22  victims  to  date,  with  the  manufacturing  sector  the  most  heavily 
targeted.  Despite  the  naming  of  two  key  members  of  INDRIK  SPIDER  in  unsealed  indictments  and 
others  in  financial  sanctions,  the  group  has  continued  to  show  resilience  in  their  campaigns. 

BitPaymer  operations  have  not  been  observed  since  mid-March  2020,  and  distribution  of  Dridex  was 
last  observed  in  late  March  2020  (CSA-200403).  The  development  and  use  of  WastedLocker  is  likely 
intended  to  distance  INDRIK  SPIDER  from  their  previous  Dridex  and  BitPaymer  operations — though 
similarities  between  BitPaymer  and  WastedLocker  suggest  such  separation  has  not  been  fully 
achieved. 


Alongside  the  identification  of  new  WastedLocker  victims,  several  other  BGH  operators  added  details 
of  their  victims  to  their  associated  DLS  this  week  (see  Figure  1). 


Figure  1.  BGH  Ransomware  Victims  by  Sector  and  Country  (26  June  to  2  July  2020) 


Commodity  Malware  Updates  and  Underground  Forum  Activity;  Stolen  Datasets 
Advertised  for  Sale 

Several  updates,  new  releases,  and  advertisements  were  identified  by  CrowdStrike  Intelligence  within 
the  past  week  on  various  criminal  and  underground  fomms  for  commodity  malware  variants  (see 
summary  in  Table  1). 


DATE 

MALWARE 

DETAILS 

24  June 

2020 

Taurus  Project 

Stealer 

Update  to  newly  released  vl  .4 

•  New  panel  includes  loader  statistics 

•  Filter  added  for  file  grabber  function 

•  Wasabi  and  Daedalus  collection  added 

•  Domain  Detect  redesigned 

24  June 

2020 

Raccoon  Stealer 

Updates  made  to  two  versions: 

•  Minor  fixes  and  improvements  to  v  1.5. 12 

•  Added  Chromium-based  Microsoft  Edge 
browser  support  for  vl.5.13 

•  Bug  fixed  affecting  auto-encryption  in 
vl.5.13 

•  Downtime  planned  between  1  and  4  July 

2020  for  back-end  update 

25  June 

2020 

Buer  Loader 

Updates  for  v  1.3. 7 

•  Runtime  cleaning 

•  Added  a  loader  directory  for  Windows 
Defender  exceptions 

•  Updated  anti-virus 

26  June 

2020 

Avaddon 

Ransomware 

Updates  to  the  build,  including 

•  Minor  improvements  and  bug  fixes 

•  Panel  access  updated 

Ongoing  recruitment  for  “networkers” 

Vendor  urged  customers  to  update  to  the  latest 
version 

26  June 

2020 

Triumph  Loader 

Update  to  vl.2.1 

•  Small  update  to  the  boot-loader 

•  General  improvements  to  the  loader 

29  June 

2020 

Amadey  Loader 

Update  to  v  1.90 

•  Lile  upload  algorithm  redesigned,  and 
number  of  attempts  to  contact  command-and- 
control  (C2)  server  increased  to  5 

•  Loader  will  reattempt  at  later  date  if  target 
server  is  busy 

29  June  2020  Oski  Stealer 

Update  to  vl.9.1,  whereby  helper  DLLs  downloaded 
from  C2  are  now  obfuscated 

Table  1.  Commodity  Malware  Updates  and  Adverts 


Also  identified  by  CrowdStrike  Intelligence  sensitive  sources  are  advertisements  for  various  stolen 
datasets.  These  advertisements  provide  a  snapshot  of  the  type  of  information  available  to  purchase  or 
acquire  from  eCrime  adversaries  that  can  be  used  to  perform  phishing  attacks  or  other  fraudulent 
activity. 

•  A  user  on  an  underground  forum  known  for  database  dumps  and  leaks  recently  shared  a  link  to 
a  dataset  sourced  from  an  Indian  e-commerce  platform.  The  data  included  personally 
identifiable  information  (PII)  and  contact  details,  including  telephone  numbers  and  postal 
addresses. 

•  On  26  June  2020,  an  Iranian  eCrime  actor  advertised  for  sale  the  business  credit  card  details 
for  a  U.S. -based  commercial  real  estate  company.  The  details  were  priced  at  $120  USD. 

•  A  user  with  a  proven  track  record  of  selling  stolen  government  and  academia-related  databases 
advertised  in  June  2020  the  sale  of  a  database  allegedly  sourced  from  the  Saudi  Ministry  of 
Interior.  The  data  includes  passport  details,  user  records,  and  some  travel-related  information. 
The  dataset  is  priced  at  $1,000  USD. 

The  Operators  of  Joker’s  Stash  and  Brian’s  Club  Release  Multiple  Offerings  of 
Compromised  Payment  Card  Information  with  PII 

The  operators  of  Joker’s  Stash  card  shop  released  one  offering  from  their  three  recent  major  breaches 
this  week,  BIGBADABOOM-III-US-part57.  CrowdStrike  Intelligence  expects  the  weekly  release  of 
compromised  payment  card  data  from  the  NEW  WORLD  ORDER,  BIGBADABOOM-III,  and 
NIRVANA  (releases  advertised  as  LOTUS)  breaches  to  continue,  based  on  the  historical  activity  of 
Joker’s  Stash  card  shop.  Additionally,  the  operators  of  Joker’s  Stash  released  four  offerings  of 
compromised  payment  card  data  that  contained  personally  PII  from  the  U.S.,  EU,  and  other 
unspecified  regions  of  the  world.  The  abbreviation  VBV  in  the  offering  highly  likely  indicates  that  it 
contains  additional  information  to  successfully  bypass  or  complete  Verified  by  Visa  (VBV)  fraud 
protection. 


DATE 

RELEASE  NAME 

REGION 

NO.  OF 

CARDS 

27  June  2020 

BIGELEPHANT-LULLINL  O- 

U.S./EU/World 

10,000 

DOB-YBV 

29  June  2020 

PINE  APPLE-FULLINFO- 
DOB-VBV 

U.S./EU/World 

15,000 

30  June  2020 

BEAUTIFULLIFE- 

FULLINFO-DOB-VBV 

U.S./EU/World 

15,000 

1  July  2020 

CULTURALSHOCK- 

FULLINFO-MIX 

U.S./EU/World 

1,000 

1  July  2020 

BIGBADABOOM-III-US- 

part57 

U.S. 

Table  2.  Recent  Joker’s  Stash  Card  Shop  Releases  for  25  June  -  2  July  2020 


From  25  June  to  2  July  2020,  CrowdStrike  Intelligence  sources  observed  the  card  shop  Brian’s  Club 
post  five  releases  of  compromised  payment  card  information  containing  PII  and  included  the 
cardholder’s  date  of  birth  (DOB)  and  Social  Security  number  (SSN). 


DATE 

RELEASE  NAME 

REGION 

PII 

25  June  2020 

0625  U  SIPS  SN 

U.S. 

DOB,  SSN 

26  June  2020 

0626  U  SIPS  SN 

U.S. 

DOB,  SSN 

27  June  2020 

0627  U S  IP  S  SN 

U.S. 

DOB,  SSN 

28  June  2020 

0628  USIPSSN 

U.S. 

DOB,  SSN 

29  June  2020 

0629  U S  IP  S  SN 

U.S. 

DOB,  SSN 

Table  3.  Brian’s  Club  PII  Offerings  for  25  June-  2  July  2020 


TARGETED  INTRUSION 


WICKED  PANDA  Deploys  RouterGod  Malware  in  Targeted  Attacks  Against 
Southeast  Asian  Entities 

As  part  of  ongoing  targeted  activity  against  Southeast  Asian  entities,  CrowdStrike  Falcon  OverWatch 
detected  the  deployment  of  novel  malware,  named  RouterGod,  at  an  entity  associated  with  the 
aviation  industry  in  Hong  Kong.  This  malware  has  likely  been  used  to  target  entities  in  Hong-Kong, 
Macau,  and  Taiwan  with  the  actor  also  deploying  additional  tools  such  as  Cobalt  Strike,  DarkShell, 
and  Proxip  as  part  of  the  same  campaign.  The  Proxip  and  Cobalt  Strike  samples  are  configured  to  use 
subdomains  of  livehost  [ .  ]  live,  a  domain  used  by  WICKED  PANDA  as  part  of  ShadowPad 
activity  targeting  Hong  Kong-based  universities  in  2019  (CSA-200151).  Because  of  the  re-use  of  this 
low  prevalence  domain,  continued  targeting  of  Southeast  Asian  entities  as  well  as  the  deployment  of 
Proxip  and  Cobalt  Strike  in  tandem,  CrowdStrike  Intelligence  currently  attributes  this  activity  to 
WICKED  PANDA  with  high  confidence. 

The  name  RouterGod  is  used  internally  by  the  malware  developers,  likely  due  to  the  ability  of  the 
malware  to  route  encrypted  command  packets  between  infected  hosts.  RouterGod  is  a  .NET 
executable  that  can  be  used  to  execute  arbitrary  scripts  as  well  as  establish  sessions  with  other  infected 
hosts.  Multiple  instances  of  the  malware  can  be  used  in  a  chain  to  deliver  implant  tasking  to  specific 
endpoints  within  victim  networks.  Additional  technical  analysis  is  available  in  CSA-200848. 


Novel  Malware  Families  Loosely  Linked  to  China  Identified 


This  week,  CrowdStrike  Intelligence  released  initial  analytic  findings  on  newly  identified  malware. 
Both  malware  families  were  used  in  operations  consistent  with  Chinese  state-nexus  activity: 

•  In  June  2020,  CrowdStrike  Falcon  OverWatch  observed  an  unknown  adversary  deploy  novel 
malware  as  part  of  an  attempted  compromise  at  a  Southeast  Asian  IT  services  provider.  The 
deployed  malware  uses  a  legitimate  antivirus  product  executable  to  gain  execution  via 
dynamic  link  library  (DLL)  search-order  hijacking  in  order  to  execute  a  malicious  loader  DLL 
that,  in  turn,  decrypts  and  loads  an  associated  payload  file.  Additional  activity  observed 
included  the  execution  of  a  Cobalt  Strike  stager  executable  that  was  used  to  download  an 
additional  payload  as  well  as  PowerShell  commands  used  to  contact  unknown  infrastructure. 
See  CSA-200849  for  more  information. 

•  Also  in  June  2020,  CrowdStrike  Falcon  OverWatch  identified  two  closely  related  incidents  at 
an  East  Asian  multinational  pharmaceutical  company.  Both  instances  featured  a  previously 
unseen  implant  linked  to  activity  CrowdStrike  has  assessed  as  consistent  with  Chinese  state 
interests.  For  this  activity,  legitimate  VirtualBox  executables  were  used  to  host  malicious 
DLLs  that  in  turn  load  and  deobfuscate  the  malicious  payloads.  See  CSA-200833  for  more 
information. 

IMPERIAL  KITTEN  Continues  Operations  Against  Probable  Saudi  Arabian 
Technology  Organizations  with  New  FireBAK  Variant 

CrowdStrike  Intelligence  has  identified  continued  activity  from  the  Iranian  state-nexus  IMPERIAL 
KITTEN  adversary  throughout  the  first  half  of  2020.  The  activity  consisted  of  the  apparent  continued 
development  of  its  FireBAK  implant,  with  new  variants  written  in  PowerShell  and  Visual  Basic  Script 
(VBS).  Additional  deployment  of  the  adversary’s  custom  LaZagne  variant  were  identified  in  late  June 
2020.  Additional  data  suggests  that  current  IMPERIAL  KITTEN  operations  likely  focus  on 
technology-related  organizations  in  Saudi  Arabia.  For  more  information,  see  CSA-200843. 

New  LampCarrier  Cluster  Activity  and  Infrastructure  Identified 

CrowdStrike  Intelligence  has  discovered  previously  unidentified  activity  attributed  to  the  LampCarrier 
cluster  including  Golang-based  malware,  a  Microsoft  Office  document  containing  a  malicious  macro, 
and  previously  unidentified  infrastructure.  Previously  observed  LampCarrier  activity  did  not  include 
malware  as  a  significant  part  of  its  toolset,  as  the  actor  preferred  to  rely  on  living-off-the  land 
techniques.  The  discovery  of  new  malware  and  malicious  documents  indicates  LampCarrier  is 
evolving  its  TTPs,  particularly  in  how  it  establishes  persistence  on  victim  networks.  Additional 
information  and  Indicators  of  Compromise  (IOCs)  are  available  in  CSA-200831. 


HACKTIVISM 


MENA  Hacktivists  Engage  in  Doxxing  and  Defacement  Activity 

On  28  June  2020,  hacktivist  group  Oman  FLackers  claimed  to  have  doxxed  more  than  20  individuals 
they  believe  responsible  for  managing  social  media  accounts  conducting  information  operations 
against  Omani  interests.  The  vast  majority  of  the  purportedly  doxxed  individuals  were  Emirati, 


although  some  citizens  of  other  countries  in  the  Middle  East  and  North  Africa  (MENA)  were  also 
identified.  The  Oman  Hackers  group  claim  to  have  obtained  this  information  by  compromising  a  fake 
account  managed  by  one  of  the  doxxed  individuals  and  then  identifying  additional  accounts  involved 
in  coordinating  inauthentic  behavior.  In  particular,  the  Oman  Hackers  group  focused  its  doxxing 
efforts  on  three  individuals  whom  the  group  believes  to  have  ties  to  various  Emirati  government  and 
security  institutions  as  well  as  some  legal  and  media  organizations.  The  Oman  Hackers  group  is 
currently  highly  active,  continuing  to  claim  that  an  organized  conspiracy  is  harming  the  Omani 
government,  its  regime,  and  the  country's  relations  with  neighboring  countries.  For  more  information, 
see  CSA-200836. 

Throughout  June  2020,  hacktivists  operating  under  the  moniker  Moroccan  Revolution  have  reported 
more  than  1200  notifications  to  the  website  defacement  archive  Zone-H.  While  the  group  has  been 
active  since  at  least  2015,  June  2020  marked  a  significant  increase  in  defacement  claims.  Only  two  of 
the  defacements  listed  in  Zone-H  records  noted  defacements  of  government  websites  in  June,  both  of 
which  were  in  Vietnam.  The  defacement  activity  is  very  likely  opportunistic  in  nature  rather  than 
specifically  targeted,  due  to  the  large  number  of  defacements  with  no  clear  geographic  or  sector 
targeting  theme.  While  CrowdStrike  Intelligence  has  not  independently  attributed  the  geographic 
origins  of  most  members  claiming  association  with  the  group,  Moroccan  Revolution  likely  consists 
broadly  of  North  African  hacktivists  or  individuals  sympathetic  to  issues  in  the  region.  Additional 
information  is  available  in  CSA-200828. 

Fallout  from  BlueLeaks  Release  of  Sensitive  U.S.  Law  Enforcement  Data 

On  19  June  2020,  hacktivist-joumalist  entity  Distributed  Denial  of  Secrets  ( DDOS)  released  269  GB 
of  materials  belonging  to  hundreds  of  law  enforcement  agencies  across  the  U.S.,  naming  the  collection 
BlueLeaks  (CSA-200801).  The  release  coincided  with  protests  against  U.S.  law  enforcement  agencies 
after  the  killing  of  George  FLOYD  on  25  May  and  follows  similar  protests  against  law  enforcement  in 
Latin  America  (LATAM).  Journalist  and  operator  of  DDOS  Emma  BEST — known  to  work  closely 
with  sophisticated  hacktivist  MOLOTOV  JACKAL  and  has  an  established  track  record  of  publishing 
materials  in  the  advancement  of  anti-capitalist  and  other  ideologies  (CSA-200663) — made  an  open 
call  for  breaches  of  U.S.  police  forces,  requesting  that  hacktivists  leak  any  exfiltrated  data  to  DDOS 
(CSA-200697).  BlueLeaks  leveraged  at  least  three  simultaneous  means  of  access  and  distribution:  a 
searchable  web  portal,  a  Tor  mirror  for  the  portal,  and  a  downloadable  Torrent  file  for  the  full 
collection;  recent  leaks  of  sensitive  law  enforcement  data  in  LATAM  were  published  in  a  similar 
manner,  with  a  user-friendly  GUI  enabling  easier  digestion  of  the  data  (CSIT- 19233). 

Among  the  BlueLeaks  data  were  sensitive  documents  belonging  to  the  Maine  Information  and 
Analysis  Center  (MIAC).  Internal  MIAC  communication  was  allegedly  not  compromised  but  results 
of  requests  for  information  (RFIs)  were  exposed,  including  personally  identifiable  information  (PII)  of 
subjects  and  victims  as  well  as  information  regarding  ongoing  investigations  in  Maine.  It  was  also 
revealed  that  MIAC  has  been  closely  tracking  Black  Lives  Matter  (BLM)  events  and  advocacy  groups 
(CSDR-20075). 

Hacktivist  Campaign  Protests  Colombian  Military  Scandal 

On  26  June  2020,  hacktivist  group  Anonymous  Colombia  posted  an  English-language  video 
announcing  a  campaign  to  protest  acts  of  extreme  violence  seven  Colombian  soldiers  committed 
against  indigenous  children.  The  group  claimed  credit  for  a  DDoS  attack  and  website  defacement 
against  two  separate  websites  belonging  to  former  Colombian  president  and  current  Senator  Alvaro 
URIBE.  A  separate  hacktivist  group  known  as  AnonymOus  China  backed  the  campaign,  claiming 
responsibility  for  a  DDoS  attack  of  the  Colombian  Army’s  English  and  Spanish-language  websites. 
This  operation  was  the  second  Anonymous-linked  #OpColombia  campaign  announced  that  week; 


there  has  been  no  observed  overlap  between  the  actors  claiming  the  activities,  highlighting  the 
decentralized  nature  of  the  Anonymous  movement.  For  more  information,  see  CSA-200839. 

Iranian  Hacktivists  Target  Israeli,  U.S.  Based  Entities 

Iranian  hacktivist  group  Death  Squads  claimed  credit  for  a  DDoS  attack  against  the  domains  of  an 
Israeli  domain  registrar  and  a  U.S. -based  bank.  As  the  veracity  and  credibility  of  these  attacks  cannot 
be  confirmed,  the  attack  and  associated  denial  of  service  were  likely  limited  in  duration  and  effect. 
Death  Squads'  latest  claims  represent  a  departure  from  past  efforts  and  are  assessed  to  likely  be 
geopolitically  motivated  due  to  the  group’s  nationalistic  outlook  and  the  backgrounds  of  its  core 
membership.  This  effort  is  likely  of  low  sophistication  and  representative  of  a  singular  hacktivist 
effort  rather  than  part  of  a  wider  campaign.  See  CSA-200837  for  more  information. 

The  timing  of  the  claim  also  coincides  with  additional  (though  apparently  unrelated)  attacks  claimed 
by  Iranian  hacktivist  groups  Vortex  Security  Team  and  Unidentified  Security  Team  against  Israel. 
Specifically,  the  groups  claimed  what  appear  to  be  two  distinct  alleged  intrusions:  one  targeting  an 
Israeli  gas  company’s  server  and  the  other  against  an  unknown  entity.  The  server  is  assessed  to  likely 
have  been  identified  via  exposed  services  or  port-scanning  activity;  the  propensity  of  hacktivists  to 
conflate  publicly  available  information  with  data  breaches  suggests  there  are  even  chances  the  extent 
of  the  intrusion  was  either  exaggerated  or  extremely  limited  in  scale.  The  hacktivist  groups  claim  that 
a  27  June  explosion  near  an  Iranian  military  base  on  24  June  was  a  result  of  an  Israeli  cyberattack,  and 
the  groups  took  retaliatory  action  in  response.  For  further  reading,  see  CSA-200840. 


DATA  EXPOSURE  &  BREACHES 


Threat  Actor  Reportedly  Selling  Data  Stolen  From  14  Companies 

A  threat  actor  is  reportedly  selling  databases  stolen  from  14  different  companies  on  an  underground 
forum,  according  to  media  reports.1  Stolen  data  varies  per  company,  though  all  breaches  reportedly 
include  usernames  and  hashed  passwords.  The  threat  actor  is  selling  the  databases  at  varying  prices, 
ranging  from  $100  to  $1,100  USD.  The  companies  were  all  allegedly  breached  in  2020,  though  the 
exact  dates  of  compromise,  if  true,  remains  unknown.  Of  the  fourteen  companies,  four  companies 
have  previously  reported  breaches.  It  is  currently  unclear  if  the  stolen  databases  from  those  four 
companies  are  connected  to  the  previously  reported  breaches. 

Eight  U.S.  Cities  Reportedly  Impacted  by  Click2Gov  Breaches 

The  local  governments  of  eight  U.S. -based  cities  discovered  a  JavaScript  (JS)  skimmer  had  been 
injected  into  the  payment  portals  of  their  Click2Gov  sites.2  The  eight  cities  were  located  across  three 
U.S.  states.  Industry  researchers  disclosed  two  different  exfiltration  servers  that  hosted  the  JS 
skimmer;  one  server  was  used  for  three  sites  and  one  used  for  the  remaining  five  sites.  The  JS 
skimmer  was  designed  to  collect  payment  card  information,  including  card  number,  expiration  date, 
and  CVY,  as  well  as  names  and  physical  addresses.  Media  reports  speculate  that  these  compromises 
are  the  result  of  a  threat  group  leveraging  Magecart  tactics.  However,  CrowdStrike  Intelligence  does 
not  currently  attribute  this  activity  to  a  known  adversary  at  this  time. 


Recent  Reporting 


CSIT-20100  Analysis  of  TRACER  KITTEN  DNSDAT  Malware  Targeting  the  Middle  Eastern 
Telecommunications  Sector 

This  Tipper  provides  technical  analysis  of  the  DNSDAT  malware  in  use  by  the  Iranian  actor  TRACER 
KITTEN. 

CSMR-20005  CrowdStrike  Intelligence  Monthly  Report  -  May  2020 

This  report  provides  significant  analytic  findings  from  May  2020,  including  trends  observed  in 
targeted  intrusion,  eCrime,  and  hacktivist  operations. 


1  https[:]//www.bleepingcomputer[.]com/news/security/seller-floods-hacker-fomm-with-data-stolen-from- 
14-companies/ 

2  https[:]//blog.trendmicro[.]com/trendlabs-security-intelligence/us-local-govemment-services-targeted- 
by-new-magecart-credit-card-skimming-attack/ 
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External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 


CSWR-20025  CrowdStrike  Intelligence  Weekly  Report:  Week 
of  06/27/2020 

On  22  July  2020,  CrowdStrike  Intelligence  will  host  the  Q2  Executive  Briefing,  an  interactive  session 
that  will  examine  some  of  the  notable  activity  and  trends  observed  during  April,  May,  and  June. 
Briefing  topics  will  include: 

•  Global  Geopolitical  Review 

•  Sector  Threat  Highlight:  Telecommunications 

•  Update  on  Ransomware  and  Data  Leaks 

•  INDRIK  SPIDER:  Post  Indictment  Changes 

•  WICKED  PANDA:  Attribution  Challenges  Posed  with  Cobalt  Strike 


Registration  details  for  the  Q2  Executive  Briefing  will  be  forthcoming  soon. 


eCRIME 


Analysis  Reveals  CARBON  SPIDER  Use  of  REvil;  JSS  Loader  Distribution 
Campaign  Observed 

Multiple  instances  of  REvil  (developed  by  PINCHY  SPIDER)  activity  in  conjunction  with  Cobalt 
Strike  have  been  attributed  with  medium  confidence  by  CrowdStrike  Intelligence  to  CARBON 
SPIDER  (CSA-200830).  The  activity  suggests  the  adversary  is  monetizing  access  to  networks  without 
Point-of-Sale  (PoS)  systems  by  encrypting  them  with  ransomware.  The  assessment  is  based  on 
overlaps  in  tooling,  infrastructure,  and  motivation.  In  particular,  multiple  connections  were  made 
through  Cobalt  Strike  samples  using  the  unique  license  identifier  452436291. 

Separately,  on  29  June  2020,  CrowdStrike  Intelligence  identified  a  Leo  VBS  (CSA-191224) 
distribution  campaign  delivering  JSS  Loader  (CSA-191 197).  While  neither  Leo  VBS  nor  JSS  Loader 
are  unique  to  a  particular  adversary,  it  is  likely  this  campaign  was  conducted  by  CARBON  SPIDER. 
This  assessment  carries  moderate  confidence  based  on  the  combination  of  Tactics,  Techniques,  and 
Procedures  (TTPs)  and  observed  command-and-control  (C2)  infrastructure  (CSA-200844). 

Criminal  Actor  Installs  Pharmaceutical-Themed  Spam  Pages  on  Compromised 
Web  Server 

On  25  June  2020,  CrowdStrike  Falcon  OverWatch  observed  hands-on  activity  conducted  by  a 
criminal  actor  at  a  North  America-based  academic  institution.  The  initial  infection  vector  of  the 
incident  is  unknown,  but  the  hands-on-activity  reveals  interesting  information  about  the  actors  TTPs 
(CSA-200834).  Throughout  25  and  26  June,  the  criminal  actor  performed  reconnaissance  activity  on 
the  host  by  checking  if  their  session  was  being  debugged,  locating  the  web  root,  and  retrieving  user 
account  names.  The  actor  proceeded  to  use  wget  to  retrieve  a  ZIP  archive  from  a  remote  location  and 
decompressed  the  archive  into  the  web  root.  The  ZIP  archive  was  over  500MB  in  size  and  contained 
more  than  30,000  pharmaceutical-themed  web  pages  advertising  various  medications  available  for 
online  purchase  without  a  prescription. 

Reportedly  New  Ransom  X  Ransomware  is  Identified  as  Defray777 

On  26  June  2020,  security  researchers  published  a  report  stating  that  a  new  ransomware  named 
Ransom  Xhad  been  used  in  an  operation  against  a  U.S. -based  government  transportation  department. 
CrowdStrike  Intelligence  has  obtained  and  analyzed  samples  of  the  reportedly  new  ransomware  and 
has  identified  the  family  as  the  existing  Defray777  (CSA-200835). 

Though  security  researchers  use  the  name  Defray777  to  refer  to  this  ransomware,  the  internal  binary 
name  set  at  compile  time — ransom,  exx — led  to  the  name  Ransom  X.  The  new  sample  displays  an 
updated  ransom  note  format.  Previously  observed  Defray777  ransom  notes  included  an  alternate 
contact  method  using  BitMessage;  however,  this  is  no  longer  present  in  the  new  ransom  note.  The 
updated  note  includes  updated  instructions  for  the  victim;  however,  the  instruction  to  “contact 
someone  from  IT  department”  remains  the  same  as  in  previous  ransom  notes. 


New  Ragnar  Locker  Victim  Post  Provides  Insight  to  TTPs;  Indications  of 
Collaborations  Between  BGH  Operators 


A  recent  post  by  VIKING  SPIDER  on  their  dedicated  leak  site  (DLS)  detailing  a  new  victim  has 
provided  insight  to  the  operator’s  TTPs  (CSA-200822).  The  post  alludes  to  the  actors  exploiting 
vulnerabilities  to  secure  initial  access  and  moving  laterally  through  the  network  after  successfully 
elevating  permissions  to  “Domain  admin”  level.  Although  the  exact  vulnerabilities  exploited  are 
unconfirmed,  the  information  provides  important  insights  to  VIKING  SPIDER’s  modus  operandi. 

There  is  increasing  evidence  of  a  collaboration  or  business  relationship  between  VIKING  SPIDER 
and  the  big  game  hunting  (BGH)  operators  TWISTED  SPIDER.  Earlier  in  June,  the  two  adversaries 
hosted  victim  information  from  each  other’s  operations  on  their  DLSs  (CSA-200745).  Both  have 
reiterated  their  intent  to  refrain  from  targeting  healthcare  entities  during  the  current  pandemic,  and 
both  draw  attention  to  their  victims’  security  issues.  This  collaborative  activity  is  unique  in  the  current 
BGH  threat  landscape,  with  Ransomware-as-a-Service  (RaaS)  and  affiliate  programs  the  more 
commonly  observed  business  arrangement. 

Spam  Campaign  Mimicking  Italian  Revenue  Agency  Distributes  Gozi  ISFB 

An  Italian-language  spam  campaign  involving  emails  mimicking  the  Italian  Revenue  Agency  was 
observed  on  29  June  2020  distributing  the  Gozi  ISFB  banking  trojan  (CSA-200842).  The  emails 
included  Excel  4.0  macro  documents,  and  referenced  two  articles  of  Italian  legislation  regarding  tax 
refunds — the  timing  of  the  campaign  was  highly  likely  intended  to  coincide  with  Italy’s  annual  tax 
deadline  of  30  June.  Phishing  campaigns  involving  Excel  4.0  macro  documents  have  become 
increasingly  popular  during  2020  (CSA-200461).  In  contrast  to  typical  macro  documents,  which 
contain  Visual  Basic  for  Applications  (VBA)  macros,  these  documents  use  Excel  4.0  macros  that 
predate  VBA  macros.  It  is  likely  adversaries  are  using  Excel  4.0  macro  documents  to  evade  email  and 
host-based  security  tools  that  are  likely  optimized  to  detect  and  prevent  embedded  VBA  macros. 

DanaBot  Sub-Botnet  4  Distributing  Avaddon  Ransomware 

SCULLY  SPIDER’s  DanaBot  sub-botnet  4  was  observed  by  CrowdStrike  Intelligence  distributing 
Avaddon  ransomware  between  22  and  30  June  2020  (CSA-200846).  This  is  the  first  instance  of  the 
sub-botnet  delivering  this  ransomware  variant — previous  payloads  delivered  by  sub-botnet  4  include 
WIZARD  SPIDER’s  Trickbot,  SMOKY  SPIDER’s  SmokeBot,  and  various  information  stealers  and 
remote  administration  tools  (RATs). 

Avaddon  has  previously  been  distributed  in  spam  campaigns,  including  one  campaign  in  June  2020 
involving  the  Phorpiex  malware  targeting  Japanese  email  addresses  (CSA-200752).  This  Avaddon 
campaign  was  seemingly  opportunistic,  with  no  explicit  sector  or  geographic  focus  identified. 

INDRIK  SPIDER’s  WastedLocker  Continues  to  Grow  Victim  Base;  BGH 
Operators  Continue  to  Add  Victim  Details  to  DLS 

INDRIK  SPIDER  has  continued  to  target  organizations  primarily  in  the  UK  and  North  America  using 
their  new  ransomware  variant  WastedLocker  (CSA-200824).  CrowdStrike  Intelligence  sensitive 
source  reporting  has  confirmed  22  victims  to  date,  with  the  manufacturing  sector  the  most  heavily 
targeted.  Despite  the  naming  of  two  key  members  of  INDRIK  SPIDER  in  unsealed  indictments  and 
others  in  financial  sanctions,  the  group  has  continued  to  show  resilience  in  their  campaigns. 

BitPaymer  operations  have  not  been  observed  since  mid-March  2020,  and  distribution  of  Dridex  was 
last  observed  in  late  March  2020  (CSA-200403).  The  development  and  use  of  WastedLocker  is  likely 
intended  to  distance  INDRIK  SPIDER  from  their  previous  Dridex  and  BitPaymer  operations — though 
similarities  between  BitPaymer  and  WastedLocker  suggest  such  separation  has  not  been  fully 
achieved. 


Alongside  the  identification  of  new  WastedLocker  victims,  several  other  BGH  operators  added  details 
of  their  victims  to  their  associated  DLS  this  week  (see  Figure  1). 


Figure  1.  BGH  Ransomware  Victims  by  Sector  and  Country  (26  June  to  2  July  2020) 


Commodity  Malware  Updates  and  Underground  Forum  Activity;  Stolen  Datasets 
Advertised  for  Sale 

Several  updates,  new  releases,  and  advertisements  were  identified  by  CrowdStrike  Intelligence  within 
the  past  week  on  various  criminal  and  underground  fomms  for  commodity  malware  variants  (see 
summary  in  Table  1). 


DATE 

MALWARE 

DETAILS 

24  June 

2020 

Taurus  Project 

Stealer 

Update  to  newly  released  vl  .4 

•  New  panel  includes  loader  statistics 

•  Filter  added  for  file  grabber  function 

•  Wasabi  and  Daedalus  collection  added 

•  Domain  Detect  redesigned 

24  June 

2020 

Raccoon  Stealer 

Updates  made  to  two  versions: 

•  Minor  fixes  and  improvements  to  v  1.5. 12 

•  Added  Chromium-based  Microsoft  Edge 
browser  support  for  vl.5.13 

•  Bug  fixed  affecting  auto-encryption  in 
vl.5.13 

•  Downtime  planned  between  1  and  4  July 

2020  for  back-end  update 

25  June 

2020 

Buer  Loader 

Updates  for  v  1.3. 7 

•  Runtime  cleaning 

•  Added  a  loader  directory  for  Windows 
Defender  exceptions 

•  Updated  anti-virus 

26  June 

2020 

Avaddon 

Ransomware 

Updates  to  the  build,  including 

•  Minor  improvements  and  bug  fixes 

•  Panel  access  updated 

Ongoing  recruitment  for  “networkers” 

Vendor  urged  customers  to  update  to  the  latest 
version 

26  June 

2020 

Triumph  Loader 

Update  to  vl.2.1 

•  Small  update  to  the  boot-loader 

•  General  improvements  to  the  loader 

29  June 

2020 

Amadey  Loader 

Update  to  v  1.90 

•  Lile  upload  algorithm  redesigned,  and 
number  of  attempts  to  contact  command-and- 
control  (C2)  server  increased  to  5 

•  Loader  will  reattempt  at  later  date  if  target 
server  is  busy 

29  June  2020  Oski  Stealer 

Update  to  vl.9.1,  whereby  helper  DLLs  downloaded 
from  C2  are  now  obfuscated 

Table  1.  Commodity  Malware  Updates  and  Adverts 


Also  identified  by  CrowdStrike  Intelligence  sensitive  sources  are  advertisements  for  various  stolen 
datasets.  These  advertisements  provide  a  snapshot  of  the  type  of  information  available  to  purchase  or 
acquire  from  eCrime  adversaries  that  can  be  used  to  perform  phishing  attacks  or  other  fraudulent 
activity. 

•  A  user  on  an  underground  forum  known  for  database  dumps  and  leaks  recently  shared  a  link  to 
a  dataset  sourced  from  an  Indian  e-commerce  platform.  The  data  included  personally 
identifiable  information  (PII)  and  contact  details,  including  telephone  numbers  and  postal 
addresses. 

•  On  26  June  2020,  an  Iranian  eCrime  actor  advertised  for  sale  the  business  credit  card  details 
for  a  U.S. -based  commercial  real  estate  company.  The  details  were  priced  at  $120  USD. 

•  A  user  with  a  proven  track  record  of  selling  stolen  government  and  academia-related  databases 
advertised  in  June  2020  the  sale  of  a  database  allegedly  sourced  from  the  Saudi  Ministry  of 
Interior.  The  data  includes  passport  details,  user  records,  and  some  travel-related  information. 
The  dataset  is  priced  at  $1,000  USD. 

The  Operators  of  Joker’s  Stash  and  Brian’s  Club  Release  Multiple  Offerings  of 
Compromised  Payment  Card  Information  with  PII 

The  operators  of  Joker’s  Stash  card  shop  released  one  offering  from  their  three  recent  major  breaches 
this  week,  BIGBADABOOM-III-US-part57.  CrowdStrike  Intelligence  expects  the  weekly  release  of 
compromised  payment  card  data  from  the  NEW  WORLD  ORDER,  BIGBADABOOM-III,  and 
NIRVANA  (releases  advertised  as  LOTUS)  breaches  to  continue,  based  on  the  historical  activity  of 
Joker’s  Stash  card  shop.  Additionally,  the  operators  of  Joker’s  Stash  released  four  offerings  of 
compromised  payment  card  data  that  contained  personally  PII  from  the  U.S.,  EU,  and  other 
unspecified  regions  of  the  world.  The  abbreviation  VBV  in  the  offering  highly  likely  indicates  that  it 
contains  additional  information  to  successfully  bypass  or  complete  Verified  by  Visa  (VBV)  fraud 
protection. 


DATE 

RELEASE  NAME 

REGION 

NO.  OF 

CARDS 

27  June  2020 

BIGELEPHANT-LULLINL  O- 

U.S./EU/World 

10,000 

DOB-YBV 

29  June  2020 

PINE  APPLE-FULLINFO- 
DOB-VBV 

U.S./EU/World 

15,000 

30  June  2020 

BEAUTIFULLIFE- 

FULLINFO-DOB-VBV 

U.S./EU/World 

15,000 

1  July  2020 

CULTURALSHOCK- 

FULLINFO-MIX 

U.S./EU/World 

1,000 

1  July  2020 

BIGBADABOOM-III-US- 

part57 

U.S. 

Table  2.  Recent  Joker’s  Stash  Card  Shop  Releases  for  25  June  -  2  July  2020 


From  25  June  to  2  July  2020,  CrowdStrike  Intelligence  sources  observed  the  card  shop  Brian’s  Club 
post  five  releases  of  compromised  payment  card  information  containing  PII  and  included  the 
cardholder’s  date  of  birth  (DOB)  and  Social  Security  number  (SSN). 


DATE 

RELEASE  NAME 

REGION 

PII 

25  June  2020 

0625  U  SIPS  SN 

U.S. 

DOB,  SSN 

26  June  2020 

0626  U  SIPS  SN 

U.S. 

DOB,  SSN 

27  June  2020 

0627  U S  IP  S  SN 

U.S. 

DOB,  SSN 

28  June  2020 

0628  USIPSSN 

U.S. 

DOB,  SSN 

29  June  2020 

0629  U S  IP  S  SN 

U.S. 

DOB,  SSN 

Table  3.  Brian’s  Club  PII  Offerings  for  25  June-  2  July  2020 


TARGETED  INTRUSION 


WICKED  PANDA  Deploys  RouterGod  Malware  in  Targeted  Attacks  Against 
Southeast  Asian  Entities 

As  part  of  ongoing  targeted  activity  against  Southeast  Asian  entities,  CrowdStrike  Falcon  OverWatch 
detected  the  deployment  of  novel  malware,  named  RouterGod,  at  an  entity  associated  with  the 
aviation  industry  in  Hong  Kong.  This  malware  has  likely  been  used  to  target  entities  in  Hong-Kong, 
Macau,  and  Taiwan  with  the  actor  also  deploying  additional  tools  such  as  Cobalt  Strike,  DarkShell, 
and  Proxip  as  part  of  the  same  campaign.  The  Proxip  and  Cobalt  Strike  samples  are  configured  to  use 
subdomains  of  livehost  [ .  ]  live,  a  domain  used  by  WICKED  PANDA  as  part  of  ShadowPad 
activity  targeting  Hong  Kong-based  universities  in  2019  (CSA-200151).  Because  of  the  re-use  of  this 
low  prevalence  domain,  continued  targeting  of  Southeast  Asian  entities  as  well  as  the  deployment  of 
Proxip  and  Cobalt  Strike  in  tandem,  CrowdStrike  Intelligence  currently  attributes  this  activity  to 
WICKED  PANDA  with  high  confidence. 

The  name  RouterGod  is  used  internally  by  the  malware  developers,  likely  due  to  the  ability  of  the 
malware  to  route  encrypted  command  packets  between  infected  hosts.  RouterGod  is  a  .NET 
executable  that  can  be  used  to  execute  arbitrary  scripts  as  well  as  establish  sessions  with  other  infected 
hosts.  Multiple  instances  of  the  malware  can  be  used  in  a  chain  to  deliver  implant  tasking  to  specific 
endpoints  within  victim  networks.  Additional  technical  analysis  is  available  in  CSA-200848. 


Novel  Malware  Families  Loosely  Linked  to  China  Identified 


This  week,  CrowdStrike  Intelligence  released  initial  analytic  findings  on  newly  identified  malware. 
Both  malware  families  were  used  in  operations  consistent  with  Chinese  state-nexus  activity: 

•  In  June  2020,  CrowdStrike  Falcon  OverWatch  observed  an  unknown  adversary  deploy  novel 
malware  as  part  of  an  attempted  compromise  at  a  Southeast  Asian  IT  services  provider.  The 
deployed  malware  uses  a  legitimate  antivirus  product  executable  to  gain  execution  via 
dynamic  link  library  (DLL)  search-order  hijacking  in  order  to  execute  a  malicious  loader  DLL 
that,  in  turn,  decrypts  and  loads  an  associated  payload  file.  Additional  activity  observed 
included  the  execution  of  a  Cobalt  Strike  stager  executable  that  was  used  to  download  an 
additional  payload  as  well  as  PowerShell  commands  used  to  contact  unknown  infrastructure. 
See  CSA-200849  for  more  information. 

•  Also  in  June  2020,  CrowdStrike  Falcon  OverWatch  identified  two  closely  related  incidents  at 
an  East  Asian  multinational  pharmaceutical  company.  Both  instances  featured  a  previously 
unseen  implant  linked  to  activity  CrowdStrike  has  assessed  as  consistent  with  Chinese  state 
interests.  For  this  activity,  legitimate  VirtualBox  executables  were  used  to  host  malicious 
DLLs  that  in  turn  load  and  deobfuscate  the  malicious  payloads.  See  CSA-200833  for  more 
information. 

IMPERIAL  KITTEN  Continues  Operations  Against  Probable  Saudi  Arabian 
Technology  Organizations  with  New  FireBAK  Variant 

CrowdStrike  Intelligence  has  identified  continued  activity  from  the  Iranian  state-nexus  IMPERIAL 
KITTEN  adversary  throughout  the  first  half  of  2020.  The  activity  consisted  of  the  apparent  continued 
development  of  its  FireBAK  implant,  with  new  variants  written  in  PowerShell  and  Visual  Basic  Script 
(VBS).  Additional  deployment  of  the  adversary’s  custom  LaZagne  variant  were  identified  in  late  June 
2020.  Additional  data  suggests  that  current  IMPERIAL  KITTEN  operations  likely  focus  on 
technology-related  organizations  in  Saudi  Arabia.  For  more  information,  see  CSA-200843. 

New  LampCarrier  Cluster  Activity  and  Infrastructure  Identified 

CrowdStrike  Intelligence  has  discovered  previously  unidentified  activity  attributed  to  the  LampCarrier 
cluster  including  Golang-based  malware,  a  Microsoft  Office  document  containing  a  malicious  macro, 
and  previously  unidentified  infrastructure.  Previously  observed  LampCarrier  activity  did  not  include 
malware  as  a  significant  part  of  its  toolset,  as  the  actor  preferred  to  rely  on  living-off-the  land 
techniques.  The  discovery  of  new  malware  and  malicious  documents  indicates  LampCarrier  is 
evolving  its  TTPs,  particularly  in  how  it  establishes  persistence  on  victim  networks.  Additional 
information  and  Indicators  of  Compromise  (IOCs)  are  available  in  CSA-200831. 


HACKTIVISM 


MENA  Hacktivists  Engage  in  Doxxing  and  Defacement  Activity 

On  28  June  2020,  hacktivist  group  Oman  FLackers  claimed  to  have  doxxed  more  than  20  individuals 
they  believe  responsible  for  managing  social  media  accounts  conducting  information  operations 
against  Omani  interests.  The  vast  majority  of  the  purportedly  doxxed  individuals  were  Emirati, 


although  some  citizens  of  other  countries  in  the  Middle  East  and  North  Africa  (MENA)  were  also 
identified.  The  Oman  Hackers  group  claim  to  have  obtained  this  information  by  compromising  a  fake 
account  managed  by  one  of  the  doxxed  individuals  and  then  identifying  additional  accounts  involved 
in  coordinating  inauthentic  behavior.  In  particular,  the  Oman  Hackers  group  focused  its  doxxing 
efforts  on  three  individuals  whom  the  group  believes  to  have  ties  to  various  Emirati  government  and 
security  institutions  as  well  as  some  legal  and  media  organizations.  The  Oman  Hackers  group  is 
currently  highly  active,  continuing  to  claim  that  an  organized  conspiracy  is  harming  the  Omani 
government,  its  regime,  and  the  country's  relations  with  neighboring  countries.  For  more  information, 
see  CSA-200836. 

Throughout  June  2020,  hacktivists  operating  under  the  moniker  Moroccan  Revolution  have  reported 
more  than  1200  notifications  to  the  website  defacement  archive  Zone-H.  While  the  group  has  been 
active  since  at  least  2015,  June  2020  marked  a  significant  increase  in  defacement  claims.  Only  two  of 
the  defacements  listed  in  Zone-H  records  noted  defacements  of  government  websites  in  June,  both  of 
which  were  in  Vietnam.  The  defacement  activity  is  very  likely  opportunistic  in  nature  rather  than 
specifically  targeted,  due  to  the  large  number  of  defacements  with  no  clear  geographic  or  sector 
targeting  theme.  While  CrowdStrike  Intelligence  has  not  independently  attributed  the  geographic 
origins  of  most  members  claiming  association  with  the  group,  Moroccan  Revolution  likely  consists 
broadly  of  North  African  hacktivists  or  individuals  sympathetic  to  issues  in  the  region.  Additional 
information  is  available  in  CSA-200828. 

Fallout  from  BlueLeaks  Release  of  Sensitive  U.S.  Law  Enforcement  Data 

On  19  June  2020,  hacktivist-joumalist  entity  Distributed  Denial  of  Secrets  ( DDOS)  released  269  GB 
of  materials  belonging  to  hundreds  of  law  enforcement  agencies  across  the  U.S.,  naming  the  collection 
BlueLeaks  (CSA-200801).  The  release  coincided  with  protests  against  U.S.  law  enforcement  agencies 
after  the  killing  of  George  FLOYD  on  25  May  and  follows  similar  protests  against  law  enforcement  in 
Latin  America  (LATAM).  Journalist  and  operator  of  DDOS  Emma  BEST — known  to  work  closely 
with  sophisticated  hacktivist  MOLOTOV  JACKAL  and  has  an  established  track  record  of  publishing 
materials  in  the  advancement  of  anti-capitalist  and  other  ideologies  (CSA-200663) — made  an  open 
call  for  breaches  of  U.S.  police  forces,  requesting  that  hacktivists  leak  any  exfiltrated  data  to  DDOS 
(CSA-200697).  BlueLeaks  leveraged  at  least  three  simultaneous  means  of  access  and  distribution:  a 
searchable  web  portal,  a  Tor  mirror  for  the  portal,  and  a  downloadable  Torrent  file  for  the  full 
collection;  recent  leaks  of  sensitive  law  enforcement  data  in  LATAM  were  published  in  a  similar 
manner,  with  a  user-friendly  GUI  enabling  easier  digestion  of  the  data  (CSIT- 19233). 

Among  the  BlueLeaks  data  were  sensitive  documents  belonging  to  the  Maine  Information  and 
Analysis  Center  (MIAC).  Internal  MIAC  communication  was  allegedly  not  compromised  but  results 
of  requests  for  information  (RFIs)  were  exposed,  including  personally  identifiable  information  (PII)  of 
subjects  and  victims  as  well  as  information  regarding  ongoing  investigations  in  Maine.  It  was  also 
revealed  that  MIAC  has  been  closely  tracking  Black  Lives  Matter  (BLM)  events  and  advocacy  groups 
(CSDR-20075). 

Hacktivist  Campaign  Protests  Colombian  Military  Scandal 

On  26  June  2020,  hacktivist  group  Anonymous  Colombia  posted  an  English-language  video 
announcing  a  campaign  to  protest  acts  of  extreme  violence  seven  Colombian  soldiers  committed 
against  indigenous  children.  The  group  claimed  credit  for  a  DDoS  attack  and  website  defacement 
against  two  separate  websites  belonging  to  former  Colombian  president  and  current  Senator  Alvaro 
URIBE.  A  separate  hacktivist  group  known  as  AnonymOus  China  backed  the  campaign,  claiming 
responsibility  for  a  DDoS  attack  of  the  Colombian  Army’s  English  and  Spanish-language  websites. 
This  operation  was  the  second  Anonymous-linked  #OpColombia  campaign  announced  that  week; 


there  has  been  no  observed  overlap  between  the  actors  claiming  the  activities,  highlighting  the 
decentralized  nature  of  the  Anonymous  movement.  For  more  information,  see  CSA-200839. 

Iranian  Hacktivists  Target  Israeli,  U.S.  Based  Entities 

Iranian  hacktivist  group  Death  Squads  claimed  credit  for  a  DDoS  attack  against  the  domains  of  an 
Israeli  domain  registrar  and  a  U.S. -based  bank.  As  the  veracity  and  credibility  of  these  attacks  cannot 
be  confirmed,  the  attack  and  associated  denial  of  service  were  likely  limited  in  duration  and  effect. 
Death  Squads'  latest  claims  represent  a  departure  from  past  efforts  and  are  assessed  to  likely  be 
geopolitically  motivated  due  to  the  group’s  nationalistic  outlook  and  the  backgrounds  of  its  core 
membership.  This  effort  is  likely  of  low  sophistication  and  representative  of  a  singular  hacktivist 
effort  rather  than  part  of  a  wider  campaign.  See  CSA-200837  for  more  information. 

The  timing  of  the  claim  also  coincides  with  additional  (though  apparently  unrelated)  attacks  claimed 
by  Iranian  hacktivist  groups  Vortex  Security  Team  and  Unidentified  Security  Team  against  Israel. 
Specifically,  the  groups  claimed  what  appear  to  be  two  distinct  alleged  intrusions:  one  targeting  an 
Israeli  gas  company’s  server  and  the  other  against  an  unknown  entity.  The  server  is  assessed  to  likely 
have  been  identified  via  exposed  services  or  port-scanning  activity;  the  propensity  of  hacktivists  to 
conflate  publicly  available  information  with  data  breaches  suggests  there  are  even  chances  the  extent 
of  the  intrusion  was  either  exaggerated  or  extremely  limited  in  scale.  The  hacktivist  groups  claim  that 
a  27  June  explosion  near  an  Iranian  military  base  on  24  June  was  a  result  of  an  Israeli  cyberattack,  and 
the  groups  took  retaliatory  action  in  response.  For  further  reading,  see  CSA-200840. 


DATA  EXPOSURE  &  BREACHES 


Threat  Actor  Reportedly  Selling  Data  Stolen  From  14  Companies 

A  threat  actor  is  reportedly  selling  databases  stolen  from  14  different  companies  on  an  underground 
forum,  according  to  media  reports.1  Stolen  data  varies  per  company,  though  all  breaches  reportedly 
include  usernames  and  hashed  passwords.  The  threat  actor  is  selling  the  databases  at  varying  prices, 
ranging  from  $100  to  $1,100  USD.  The  companies  were  all  allegedly  breached  in  2020,  though  the 
exact  dates  of  compromise,  if  true,  remains  unknown.  Of  the  fourteen  companies,  four  companies 
have  previously  reported  breaches.  It  is  currently  unclear  if  the  stolen  databases  from  those  four 
companies  are  connected  to  the  previously  reported  breaches. 

Eight  U.S.  Cities  Reportedly  Impacted  by  Click2Gov  Breaches 

The  local  governments  of  eight  U.S. -based  cities  discovered  a  JavaScript  (JS)  skimmer  had  been 
injected  into  the  payment  portals  of  their  Click2Gov  sites.2  The  eight  cities  were  located  across  three 
U.S.  states.  Industry  researchers  disclosed  two  different  exfiltration  servers  that  hosted  the  JS 
skimmer;  one  server  was  used  for  three  sites  and  one  used  for  the  remaining  five  sites.  The  JS 
skimmer  was  designed  to  collect  payment  card  information,  including  card  number,  expiration  date, 
and  CVY,  as  well  as  names  and  physical  addresses.  Media  reports  speculate  that  these  compromises 
are  the  result  of  a  threat  group  leveraging  Magecart  tactics.  However,  CrowdStrike  Intelligence  does 
not  currently  attribute  this  activity  to  a  known  adversary  at  this  time. 


Recent  Reporting 


CSIT-20100  Analysis  of  TRACER  KITTEN  DNSDAT  Malware  Targeting  the  Middle  Eastern 
Telecommunications  Sector 

This  Tipper  provides  technical  analysis  of  the  DNSDAT  malware  in  use  by  the  Iranian  actor  TRACER 
KITTEN. 

CSMR-20005  CrowdStrike  Intelligence  Monthly  Report  -  May  2020 

This  report  provides  significant  analytic  findings  from  May  2020,  including  trends  observed  in 
targeted  intrusion,  eCrime,  and  hacktivist  operations. 


1  https[:]//www.bleepingcomputer[.]com/news/security/seller-floods-hacker-fomm-with-data-stolen-from- 
14-companies/ 

2  https[:]//blog.trendmicro[.]com/trendlabs-security-intelligence/us-local-govemment-services-targeted- 
by-new-magecart-credit-card-skimming-attack/ 
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This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 


CSWR-20025  CrowdStrike  Intelligence  Weekly  Report:  Week 
of  06/27/2020 

On  22  July  2020,  CrowdStrike  Intelligence  will  host  the  Q2  Executive  Briefing,  an  interactive  session 
that  will  examine  some  of  the  notable  activity  and  trends  observed  during  April,  May,  and  June. 
Briefing  topics  will  include: 

•  Global  Geopolitical  Review 

•  Sector  Threat  Highlight:  Telecommunications 

•  Update  on  Ransomware  and  Data  Leaks 

•  INDRIK  SPIDER:  Post  Indictment  Changes 

•  WICKED  PANDA:  Attribution  Challenges  Posed  with  Cobalt  Strike 


Registration  details  for  the  Q2  Executive  Briefing  will  be  forthcoming  soon. 


eCRIME 


Analysis  Reveals  CARBON  SPIDER  Use  of  REvil;  JSS  Loader  Distribution 
Campaign  Observed 

Multiple  instances  of  REvil  (developed  by  PINCHY  SPIDER)  activity  in  conjunction  with  Cobalt 
Strike  have  been  attributed  with  medium  confidence  by  CrowdStrike  Intelligence  to  CARBON 
SPIDER  (CSA-200830).  The  activity  suggests  the  adversary  is  monetizing  access  to  networks  without 
Point-of-Sale  (PoS)  systems  by  encrypting  them  with  ransomware.  The  assessment  is  based  on 
overlaps  in  tooling,  infrastructure,  and  motivation.  In  particular,  multiple  connections  were  made 
through  Cobalt  Strike  samples  using  the  unique  license  identifier  452436291. 

Separately,  on  29  June  2020,  CrowdStrike  Intelligence  identified  a  Leo  VBS  (CSA-191224) 
distribution  campaign  delivering  JSS  Loader  (CSA-191 197).  While  neither  Leo  VBS  nor  JSS  Loader 
are  unique  to  a  particular  adversary,  it  is  likely  this  campaign  was  conducted  by  CARBON  SPIDER. 
This  assessment  carries  moderate  confidence  based  on  the  combination  of  Tactics,  Techniques,  and 
Procedures  (TTPs)  and  observed  command-and-control  (C2)  infrastructure  (CSA-200844). 

Criminal  Actor  Installs  Pharmaceutical-Themed  Spam  Pages  on  Compromised 
Web  Server 

On  25  June  2020,  CrowdStrike  Falcon  OverWatch  observed  hands-on  activity  conducted  by  a 
criminal  actor  at  a  North  America-based  academic  institution.  The  initial  infection  vector  of  the 
incident  is  unknown,  but  the  hands-on-activity  reveals  interesting  information  about  the  actors  TTPs 
(CSA-200834).  Throughout  25  and  26  June,  the  criminal  actor  performed  reconnaissance  activity  on 
the  host  by  checking  if  their  session  was  being  debugged,  locating  the  web  root,  and  retrieving  user 
account  names.  The  actor  proceeded  to  use  wget  to  retrieve  a  ZIP  archive  from  a  remote  location  and 
decompressed  the  archive  into  the  web  root.  The  ZIP  archive  was  over  500MB  in  size  and  contained 
more  than  30,000  pharmaceutical-themed  web  pages  advertising  various  medications  available  for 
online  purchase  without  a  prescription. 

Reportedly  New  Ransom  X  Ransomware  is  Identified  as  Defray777 

On  26  June  2020,  security  researchers  published  a  report  stating  that  a  new  ransomware  named 
Ransom  Xhad  been  used  in  an  operation  against  a  U.S. -based  government  transportation  department. 
CrowdStrike  Intelligence  has  obtained  and  analyzed  samples  of  the  reportedly  new  ransomware  and 
has  identified  the  family  as  the  existing  Defray777  (CSA-200835). 

Though  security  researchers  use  the  name  Defray777  to  refer  to  this  ransomware,  the  internal  binary 
name  set  at  compile  time — ransom,  exx — led  to  the  name  Ransom  X.  The  new  sample  displays  an 
updated  ransom  note  format.  Previously  observed  Defray777  ransom  notes  included  an  alternate 
contact  method  using  BitMessage;  however,  this  is  no  longer  present  in  the  new  ransom  note.  The 
updated  note  includes  updated  instructions  for  the  victim;  however,  the  instruction  to  “contact 
someone  from  IT  department”  remains  the  same  as  in  previous  ransom  notes. 


New  Ragnar  Locker  Victim  Post  Provides  Insight  to  TTPs;  Indications  of 
Collaborations  Between  BGH  Operators 


A  recent  post  by  VIKING  SPIDER  on  their  dedicated  leak  site  (DLS)  detailing  a  new  victim  has 
provided  insight  to  the  operator’s  TTPs  (CSA-200822).  The  post  alludes  to  the  actors  exploiting 
vulnerabilities  to  secure  initial  access  and  moving  laterally  through  the  network  after  successfully 
elevating  permissions  to  “Domain  admin”  level.  Although  the  exact  vulnerabilities  exploited  are 
unconfirmed,  the  information  provides  important  insights  to  VIKING  SPIDER’s  modus  operandi. 

There  is  increasing  evidence  of  a  collaboration  or  business  relationship  between  VIKING  SPIDER 
and  the  big  game  hunting  (BGH)  operators  TWISTED  SPIDER.  Earlier  in  June,  the  two  adversaries 
hosted  victim  information  from  each  other’s  operations  on  their  DLSs  (CSA-200745).  Both  have 
reiterated  their  intent  to  refrain  from  targeting  healthcare  entities  during  the  current  pandemic,  and 
both  draw  attention  to  their  victims’  security  issues.  This  collaborative  activity  is  unique  in  the  current 
BGH  threat  landscape,  with  Ransomware-as-a-Service  (RaaS)  and  affiliate  programs  the  more 
commonly  observed  business  arrangement. 

Spam  Campaign  Mimicking  Italian  Revenue  Agency  Distributes  Gozi  ISFB 

An  Italian-language  spam  campaign  involving  emails  mimicking  the  Italian  Revenue  Agency  was 
observed  on  29  June  2020  distributing  the  Gozi  ISFB  banking  trojan  (CSA-200842).  The  emails 
included  Excel  4.0  macro  documents,  and  referenced  two  articles  of  Italian  legislation  regarding  tax 
refunds — the  timing  of  the  campaign  was  highly  likely  intended  to  coincide  with  Italy’s  annual  tax 
deadline  of  30  June.  Phishing  campaigns  involving  Excel  4.0  macro  documents  have  become 
increasingly  popular  during  2020  (CSA-200461).  In  contrast  to  typical  macro  documents,  which 
contain  Visual  Basic  for  Applications  (VBA)  macros,  these  documents  use  Excel  4.0  macros  that 
predate  VBA  macros.  It  is  likely  adversaries  are  using  Excel  4.0  macro  documents  to  evade  email  and 
host-based  security  tools  that  are  likely  optimized  to  detect  and  prevent  embedded  VBA  macros. 

DanaBot  Sub-Botnet  4  Distributing  Avaddon  Ransomware 

SCULLY  SPIDER’s  DanaBot  sub-botnet  4  was  observed  by  CrowdStrike  Intelligence  distributing 
Avaddon  ransomware  between  22  and  30  June  2020  (CSA-200846).  This  is  the  first  instance  of  the 
sub-botnet  delivering  this  ransomware  variant — previous  payloads  delivered  by  sub-botnet  4  include 
WIZARD  SPIDER’s  Trickbot,  SMOKY  SPIDER’s  SmokeBot,  and  various  information  stealers  and 
remote  administration  tools  (RATs). 

Avaddon  has  previously  been  distributed  in  spam  campaigns,  including  one  campaign  in  June  2020 
involving  the  Phorpiex  malware  targeting  Japanese  email  addresses  (CSA-200752).  This  Avaddon 
campaign  was  seemingly  opportunistic,  with  no  explicit  sector  or  geographic  focus  identified. 

INDRIK  SPIDER’s  WastedLocker  Continues  to  Grow  Victim  Base;  BGH 
Operators  Continue  to  Add  Victim  Details  to  DLS 

INDRIK  SPIDER  has  continued  to  target  organizations  primarily  in  the  UK  and  North  America  using 
their  new  ransomware  variant  WastedLocker  (CSA-200824).  CrowdStrike  Intelligence  sensitive 
source  reporting  has  confirmed  22  victims  to  date,  with  the  manufacturing  sector  the  most  heavily 
targeted.  Despite  the  naming  of  two  key  members  of  INDRIK  SPIDER  in  unsealed  indictments  and 
others  in  financial  sanctions,  the  group  has  continued  to  show  resilience  in  their  campaigns. 

BitPaymer  operations  have  not  been  observed  since  mid-March  2020,  and  distribution  of  Dridex  was 
last  observed  in  late  March  2020  (CSA-200403).  The  development  and  use  of  WastedLocker  is  likely 
intended  to  distance  INDRIK  SPIDER  from  their  previous  Dridex  and  BitPaymer  operations — though 
similarities  between  BitPaymer  and  WastedLocker  suggest  such  separation  has  not  been  fully 
achieved. 


Alongside  the  identification  of  new  WastedLocker  victims,  several  other  BGH  operators  added  details 
of  their  victims  to  their  associated  DLS  this  week  (see  Figure  1). 


Figure  1.  BGH  Ransomware  Victims  by  Sector  and  Country  (26  June  to  2  July  2020) 


Commodity  Malware  Updates  and  Underground  Forum  Activity;  Stolen  Datasets 
Advertised  for  Sale 

Several  updates,  new  releases,  and  advertisements  were  identified  by  CrowdStrike  Intelligence  within 
the  past  week  on  various  criminal  and  underground  fomms  for  commodity  malware  variants  (see 
summary  in  Table  1). 


DATE 

MALWARE 

DETAILS 

24  June 

2020 

Taurus  Project 

Stealer 

Update  to  newly  released  vl  .4 

•  New  panel  includes  loader  statistics 

•  Filter  added  for  file  grabber  function 

•  Wasabi  and  Daedalus  collection  added 

•  Domain  Detect  redesigned 

24  June 

2020 

Raccoon  Stealer 

Updates  made  to  two  versions: 

•  Minor  fixes  and  improvements  to  v  1.5. 12 

•  Added  Chromium-based  Microsoft  Edge 
browser  support  for  vl.5.13 

•  Bug  fixed  affecting  auto-encryption  in 
vl.5.13 

•  Downtime  planned  between  1  and  4  July 

2020  for  back-end  update 

25  June 

2020 

Buer  Loader 

Updates  for  v  1.3. 7 

•  Runtime  cleaning 

•  Added  a  loader  directory  for  Windows 
Defender  exceptions 

•  Updated  anti-virus 

26  June 

2020 

Avaddon 

Ransomware 

Updates  to  the  build,  including 

•  Minor  improvements  and  bug  fixes 

•  Panel  access  updated 

Ongoing  recruitment  for  “networkers” 

Vendor  urged  customers  to  update  to  the  latest 
version 

26  June 

2020 

Triumph  Loader 

Update  to  vl.2.1 

•  Small  update  to  the  boot-loader 

•  General  improvements  to  the  loader 

29  June 

2020 

Amadey  Loader 

Update  to  v  1.90 

•  Lile  upload  algorithm  redesigned,  and 
number  of  attempts  to  contact  command-and- 
control  (C2)  server  increased  to  5 

•  Loader  will  reattempt  at  later  date  if  target 
server  is  busy 

29  June  2020  Oski  Stealer 

Update  to  vl.9.1,  whereby  helper  DLLs  downloaded 
from  C2  are  now  obfuscated 

Table  1.  Commodity  Malware  Updates  and  Adverts 


Also  identified  by  CrowdStrike  Intelligence  sensitive  sources  are  advertisements  for  various  stolen 
datasets.  These  advertisements  provide  a  snapshot  of  the  type  of  information  available  to  purchase  or 
acquire  from  eCrime  adversaries  that  can  be  used  to  perform  phishing  attacks  or  other  fraudulent 
activity. 

•  A  user  on  an  underground  forum  known  for  database  dumps  and  leaks  recently  shared  a  link  to 
a  dataset  sourced  from  an  Indian  e-commerce  platform.  The  data  included  personally 
identifiable  information  (PII)  and  contact  details,  including  telephone  numbers  and  postal 
addresses. 

•  On  26  June  2020,  an  Iranian  eCrime  actor  advertised  for  sale  the  business  credit  card  details 
for  a  U.S. -based  commercial  real  estate  company.  The  details  were  priced  at  $120  USD. 

•  A  user  with  a  proven  track  record  of  selling  stolen  government  and  academia-related  databases 
advertised  in  June  2020  the  sale  of  a  database  allegedly  sourced  from  the  Saudi  Ministry  of 
Interior.  The  data  includes  passport  details,  user  records,  and  some  travel-related  information. 
The  dataset  is  priced  at  $1,000  USD. 

The  Operators  of  Joker’s  Stash  and  Brian’s  Club  Release  Multiple  Offerings  of 
Compromised  Payment  Card  Information  with  PII 

The  operators  of  Joker’s  Stash  card  shop  released  one  offering  from  their  three  recent  major  breaches 
this  week,  BIGBADABOOM-III-US-part57.  CrowdStrike  Intelligence  expects  the  weekly  release  of 
compromised  payment  card  data  from  the  NEW  WORLD  ORDER,  BIGBADABOOM-III,  and 
NIRVANA  (releases  advertised  as  LOTUS)  breaches  to  continue,  based  on  the  historical  activity  of 
Joker’s  Stash  card  shop.  Additionally,  the  operators  of  Joker’s  Stash  released  four  offerings  of 
compromised  payment  card  data  that  contained  personally  PII  from  the  U.S.,  EU,  and  other 
unspecified  regions  of  the  world.  The  abbreviation  VBV  in  the  offering  highly  likely  indicates  that  it 
contains  additional  information  to  successfully  bypass  or  complete  Verified  by  Visa  (VBV)  fraud 
protection. 


DATE 

RELEASE  NAME 

REGION 

NO.  OF 

CARDS 

27  June  2020 

BIGELEPHANT-LULLINL  O- 

U.S./EU/World 

10,000 

DOB-YBV 

29  June  2020 

PINE  APPLE-FULLINFO- 
DOB-VBV 

U.S./EU/World 

15,000 

30  June  2020 

BEAUTIFULLIFE- 

FULLINFO-DOB-VBV 

U.S./EU/World 

15,000 

1  July  2020 

CULTURALSHOCK- 

FULLINFO-MIX 

U.S./EU/World 

1,000 

1  July  2020 

BIGBADABOOM-III-US- 

part57 

U.S. 

Table  2.  Recent  Joker’s  Stash  Card  Shop  Releases  for  25  June  -  2  July  2020 


From  25  June  to  2  July  2020,  CrowdStrike  Intelligence  sources  observed  the  card  shop  Brian’s  Club 
post  five  releases  of  compromised  payment  card  information  containing  PII  and  included  the 
cardholder’s  date  of  birth  (DOB)  and  Social  Security  number  (SSN). 


DATE 

RELEASE  NAME 

REGION 

PII 

25  June  2020 

0625  U  SIPS  SN 

U.S. 

DOB,  SSN 

26  June  2020 

0626  U  SIPS  SN 

U.S. 

DOB,  SSN 

27  June  2020 

0627  U S  IP  S  SN 

U.S. 

DOB,  SSN 

28  June  2020 

0628  USIPSSN 

U.S. 

DOB,  SSN 

29  June  2020 

0629  U S  IP  S  SN 

U.S. 

DOB,  SSN 

Table  3.  Brian’s  Club  PII  Offerings  for  25  June-  2  July  2020 


TARGETED  INTRUSION 


WICKED  PANDA  Deploys  RouterGod  Malware  in  Targeted  Attacks  Against 
Southeast  Asian  Entities 

As  part  of  ongoing  targeted  activity  against  Southeast  Asian  entities,  CrowdStrike  Falcon  OverWatch 
detected  the  deployment  of  novel  malware,  named  RouterGod,  at  an  entity  associated  with  the 
aviation  industry  in  Hong  Kong.  This  malware  has  likely  been  used  to  target  entities  in  Hong-Kong, 
Macau,  and  Taiwan  with  the  actor  also  deploying  additional  tools  such  as  Cobalt  Strike,  DarkShell, 
and  Proxip  as  part  of  the  same  campaign.  The  Proxip  and  Cobalt  Strike  samples  are  configured  to  use 
subdomains  of  livehost  [ .  ]  live,  a  domain  used  by  WICKED  PANDA  as  part  of  ShadowPad 
activity  targeting  Hong  Kong-based  universities  in  2019  (CSA-200151).  Because  of  the  re-use  of  this 
low  prevalence  domain,  continued  targeting  of  Southeast  Asian  entities  as  well  as  the  deployment  of 
Proxip  and  Cobalt  Strike  in  tandem,  CrowdStrike  Intelligence  currently  attributes  this  activity  to 
WICKED  PANDA  with  high  confidence. 

The  name  RouterGod  is  used  internally  by  the  malware  developers,  likely  due  to  the  ability  of  the 
malware  to  route  encrypted  command  packets  between  infected  hosts.  RouterGod  is  a  .NET 
executable  that  can  be  used  to  execute  arbitrary  scripts  as  well  as  establish  sessions  with  other  infected 
hosts.  Multiple  instances  of  the  malware  can  be  used  in  a  chain  to  deliver  implant  tasking  to  specific 
endpoints  within  victim  networks.  Additional  technical  analysis  is  available  in  CSA-200848. 


Novel  Malware  Families  Loosely  Linked  to  China  Identified 


This  week,  CrowdStrike  Intelligence  released  initial  analytic  findings  on  newly  identified  malware. 
Both  malware  families  were  used  in  operations  consistent  with  Chinese  state-nexus  activity: 

•  In  June  2020,  CrowdStrike  Falcon  OverWatch  observed  an  unknown  adversary  deploy  novel 
malware  as  part  of  an  attempted  compromise  at  a  Southeast  Asian  IT  services  provider.  The 
deployed  malware  uses  a  legitimate  antivirus  product  executable  to  gain  execution  via 
dynamic  link  library  (DLL)  search-order  hijacking  in  order  to  execute  a  malicious  loader  DLL 
that,  in  turn,  decrypts  and  loads  an  associated  payload  file.  Additional  activity  observed 
included  the  execution  of  a  Cobalt  Strike  stager  executable  that  was  used  to  download  an 
additional  payload  as  well  as  PowerShell  commands  used  to  contact  unknown  infrastructure. 
See  CSA-200849  for  more  information. 

•  Also  in  June  2020,  CrowdStrike  Falcon  OverWatch  identified  two  closely  related  incidents  at 
an  East  Asian  multinational  pharmaceutical  company.  Both  instances  featured  a  previously 
unseen  implant  linked  to  activity  CrowdStrike  has  assessed  as  consistent  with  Chinese  state 
interests.  For  this  activity,  legitimate  VirtualBox  executables  were  used  to  host  malicious 
DLLs  that  in  turn  load  and  deobfuscate  the  malicious  payloads.  See  CSA-200833  for  more 
information. 

IMPERIAL  KITTEN  Continues  Operations  Against  Probable  Saudi  Arabian 
Technology  Organizations  with  New  FireBAK  Variant 

CrowdStrike  Intelligence  has  identified  continued  activity  from  the  Iranian  state-nexus  IMPERIAL 
KITTEN  adversary  throughout  the  first  half  of  2020.  The  activity  consisted  of  the  apparent  continued 
development  of  its  FireBAK  implant,  with  new  variants  written  in  PowerShell  and  Visual  Basic  Script 
(VBS).  Additional  deployment  of  the  adversary’s  custom  LaZagne  variant  were  identified  in  late  June 
2020.  Additional  data  suggests  that  current  IMPERIAL  KITTEN  operations  likely  focus  on 
technology-related  organizations  in  Saudi  Arabia.  For  more  information,  see  CSA-200843. 

New  LampCarrier  Cluster  Activity  and  Infrastructure  Identified 

CrowdStrike  Intelligence  has  discovered  previously  unidentified  activity  attributed  to  the  LampCarrier 
cluster  including  Golang-based  malware,  a  Microsoft  Office  document  containing  a  malicious  macro, 
and  previously  unidentified  infrastructure.  Previously  observed  LampCarrier  activity  did  not  include 
malware  as  a  significant  part  of  its  toolset,  as  the  actor  preferred  to  rely  on  living-off-the  land 
techniques.  The  discovery  of  new  malware  and  malicious  documents  indicates  LampCarrier  is 
evolving  its  TTPs,  particularly  in  how  it  establishes  persistence  on  victim  networks.  Additional 
information  and  Indicators  of  Compromise  (IOCs)  are  available  in  CSA-200831. 


HACKTIVISM 


MENA  Hacktivists  Engage  in  Doxxing  and  Defacement  Activity 

On  28  June  2020,  hacktivist  group  Oman  FLackers  claimed  to  have  doxxed  more  than  20  individuals 
they  believe  responsible  for  managing  social  media  accounts  conducting  information  operations 
against  Omani  interests.  The  vast  majority  of  the  purportedly  doxxed  individuals  were  Emirati, 


although  some  citizens  of  other  countries  in  the  Middle  East  and  North  Africa  (MENA)  were  also 
identified.  The  Oman  Hackers  group  claim  to  have  obtained  this  information  by  compromising  a  fake 
account  managed  by  one  of  the  doxxed  individuals  and  then  identifying  additional  accounts  involved 
in  coordinating  inauthentic  behavior.  In  particular,  the  Oman  Hackers  group  focused  its  doxxing 
efforts  on  three  individuals  whom  the  group  believes  to  have  ties  to  various  Emirati  government  and 
security  institutions  as  well  as  some  legal  and  media  organizations.  The  Oman  Hackers  group  is 
currently  highly  active,  continuing  to  claim  that  an  organized  conspiracy  is  harming  the  Omani 
government,  its  regime,  and  the  country's  relations  with  neighboring  countries.  For  more  information, 
see  CSA-200836. 

Throughout  June  2020,  hacktivists  operating  under  the  moniker  Moroccan  Revolution  have  reported 
more  than  1200  notifications  to  the  website  defacement  archive  Zone-H.  While  the  group  has  been 
active  since  at  least  2015,  June  2020  marked  a  significant  increase  in  defacement  claims.  Only  two  of 
the  defacements  listed  in  Zone-H  records  noted  defacements  of  government  websites  in  June,  both  of 
which  were  in  Vietnam.  The  defacement  activity  is  very  likely  opportunistic  in  nature  rather  than 
specifically  targeted,  due  to  the  large  number  of  defacements  with  no  clear  geographic  or  sector 
targeting  theme.  While  CrowdStrike  Intelligence  has  not  independently  attributed  the  geographic 
origins  of  most  members  claiming  association  with  the  group,  Moroccan  Revolution  likely  consists 
broadly  of  North  African  hacktivists  or  individuals  sympathetic  to  issues  in  the  region.  Additional 
information  is  available  in  CSA-200828. 

Fallout  from  BlueLeaks  Release  of  Sensitive  U.S.  Law  Enforcement  Data 

On  19  June  2020,  hacktivist-joumalist  entity  Distributed  Denial  of  Secrets  ( DDOS)  released  269  GB 
of  materials  belonging  to  hundreds  of  law  enforcement  agencies  across  the  U.S.,  naming  the  collection 
BlueLeaks  (CSA-200801).  The  release  coincided  with  protests  against  U.S.  law  enforcement  agencies 
after  the  killing  of  George  FLOYD  on  25  May  and  follows  similar  protests  against  law  enforcement  in 
Latin  America  (LATAM).  Journalist  and  operator  of  DDOS  Emma  BEST — known  to  work  closely 
with  sophisticated  hacktivist  MOLOTOV  JACKAL  and  has  an  established  track  record  of  publishing 
materials  in  the  advancement  of  anti-capitalist  and  other  ideologies  (CSA-200663) — made  an  open 
call  for  breaches  of  U.S.  police  forces,  requesting  that  hacktivists  leak  any  exfiltrated  data  to  DDOS 
(CSA-200697).  BlueLeaks  leveraged  at  least  three  simultaneous  means  of  access  and  distribution:  a 
searchable  web  portal,  a  Tor  mirror  for  the  portal,  and  a  downloadable  Torrent  file  for  the  full 
collection;  recent  leaks  of  sensitive  law  enforcement  data  in  LATAM  were  published  in  a  similar 
manner,  with  a  user-friendly  GUI  enabling  easier  digestion  of  the  data  (CSIT- 19233). 

Among  the  BlueLeaks  data  were  sensitive  documents  belonging  to  the  Maine  Information  and 
Analysis  Center  (MIAC).  Internal  MIAC  communication  was  allegedly  not  compromised  but  results 
of  requests  for  information  (RFIs)  were  exposed,  including  personally  identifiable  information  (PII)  of 
subjects  and  victims  as  well  as  information  regarding  ongoing  investigations  in  Maine.  It  was  also 
revealed  that  MIAC  has  been  closely  tracking  Black  Lives  Matter  (BLM)  events  and  advocacy  groups 
(CSDR-20075). 

Hacktivist  Campaign  Protests  Colombian  Military  Scandal 

On  26  June  2020,  hacktivist  group  Anonymous  Colombia  posted  an  English-language  video 
announcing  a  campaign  to  protest  acts  of  extreme  violence  seven  Colombian  soldiers  committed 
against  indigenous  children.  The  group  claimed  credit  for  a  DDoS  attack  and  website  defacement 
against  two  separate  websites  belonging  to  former  Colombian  president  and  current  Senator  Alvaro 
URIBE.  A  separate  hacktivist  group  known  as  AnonymOus  China  backed  the  campaign,  claiming 
responsibility  for  a  DDoS  attack  of  the  Colombian  Army’s  English  and  Spanish-language  websites. 
This  operation  was  the  second  Anonymous-linked  #OpColombia  campaign  announced  that  week; 


there  has  been  no  observed  overlap  between  the  actors  claiming  the  activities,  highlighting  the 
decentralized  nature  of  the  Anonymous  movement.  For  more  information,  see  CSA-200839. 

Iranian  Hacktivists  Target  Israeli,  U.S.  Based  Entities 

Iranian  hacktivist  group  Death  Squads  claimed  credit  for  a  DDoS  attack  against  the  domains  of  an 
Israeli  domain  registrar  and  a  U.S. -based  bank.  As  the  veracity  and  credibility  of  these  attacks  cannot 
be  confirmed,  the  attack  and  associated  denial  of  service  were  likely  limited  in  duration  and  effect. 
Death  Squads'  latest  claims  represent  a  departure  from  past  efforts  and  are  assessed  to  likely  be 
geopolitically  motivated  due  to  the  group’s  nationalistic  outlook  and  the  backgrounds  of  its  core 
membership.  This  effort  is  likely  of  low  sophistication  and  representative  of  a  singular  hacktivist 
effort  rather  than  part  of  a  wider  campaign.  See  CSA-200837  for  more  information. 

The  timing  of  the  claim  also  coincides  with  additional  (though  apparently  unrelated)  attacks  claimed 
by  Iranian  hacktivist  groups  Vortex  Security  Team  and  Unidentified  Security  Team  against  Israel. 
Specifically,  the  groups  claimed  what  appear  to  be  two  distinct  alleged  intrusions:  one  targeting  an 
Israeli  gas  company’s  server  and  the  other  against  an  unknown  entity.  The  server  is  assessed  to  likely 
have  been  identified  via  exposed  services  or  port-scanning  activity;  the  propensity  of  hacktivists  to 
conflate  publicly  available  information  with  data  breaches  suggests  there  are  even  chances  the  extent 
of  the  intrusion  was  either  exaggerated  or  extremely  limited  in  scale.  The  hacktivist  groups  claim  that 
a  27  June  explosion  near  an  Iranian  military  base  on  24  June  was  a  result  of  an  Israeli  cyberattack,  and 
the  groups  took  retaliatory  action  in  response.  For  further  reading,  see  CSA-200840. 


DATA  EXPOSURE  &  BREACHES 


Threat  Actor  Reportedly  Selling  Data  Stolen  From  14  Companies 

A  threat  actor  is  reportedly  selling  databases  stolen  from  14  different  companies  on  an  underground 
forum,  according  to  media  reports.1  Stolen  data  varies  per  company,  though  all  breaches  reportedly 
include  usernames  and  hashed  passwords.  The  threat  actor  is  selling  the  databases  at  varying  prices, 
ranging  from  $100  to  $1,100  USD.  The  companies  were  all  allegedly  breached  in  2020,  though  the 
exact  dates  of  compromise,  if  true,  remains  unknown.  Of  the  fourteen  companies,  four  companies 
have  previously  reported  breaches.  It  is  currently  unclear  if  the  stolen  databases  from  those  four 
companies  are  connected  to  the  previously  reported  breaches. 

Eight  U.S.  Cities  Reportedly  Impacted  by  Click2Gov  Breaches 

The  local  governments  of  eight  U.S. -based  cities  discovered  a  JavaScript  (JS)  skimmer  had  been 
injected  into  the  payment  portals  of  their  Click2Gov  sites.2  The  eight  cities  were  located  across  three 
U.S.  states.  Industry  researchers  disclosed  two  different  exfiltration  servers  that  hosted  the  JS 
skimmer;  one  server  was  used  for  three  sites  and  one  used  for  the  remaining  five  sites.  The  JS 
skimmer  was  designed  to  collect  payment  card  information,  including  card  number,  expiration  date, 
and  CVY,  as  well  as  names  and  physical  addresses.  Media  reports  speculate  that  these  compromises 
are  the  result  of  a  threat  group  leveraging  Magecart  tactics.  However,  CrowdStrike  Intelligence  does 
not  currently  attribute  this  activity  to  a  known  adversary  at  this  time. 


Recent  Reporting 


CSIT-20100  Analysis  of  TRACER  KITTEN  DNSDAT  Malware  Targeting  the  Middle  Eastern 
Telecommunications  Sector 

This  Tipper  provides  technical  analysis  of  the  DNSDAT  malware  in  use  by  the  Iranian  actor  TRACER 
KITTEN. 

CSMR-20005  CrowdStrike  Intelligence  Monthly  Report  -  May  2020 

This  report  provides  significant  analytic  findings  from  May  2020,  including  trends  observed  in 
targeted  intrusion,  eCrime,  and  hacktivist  operations. 


1  https[:]//www.bleepingcomputer[.]com/news/security/seller-floods-hacker-fomm-with-data-stolen-from- 
14-companies/ 

2  https[:]//blog.trendmicro[.]com/trendlabs-security-intelligence/us-local-govemment-services-targeted- 
by-new-magecart-credit-card-skimming-attack/ 
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CSWR-20025  CrowdStrike  Intelligence  Weekly  Report:  Week  of  06/27/2020 

To:  Jonathan  Springborn  (Sheriff),  Keith  Morrison  (Sheriff),  Christopher  Moore  (Sheriff) 

Sent:  July  3,  2020  3:33:1 9  PM  CDT 

Received:  July  3,  2020  3:33:24  PM  CDT 


[GovQA]  FOIA  Request  -  Activity  Assignment  — ::  R0091 42-062920  -  4766 

From:  Cook  County  Sheriff's  Office  <cookcountysheriff@govqa.us> 

To:  Christopher.Seaman@cookcountyil.gov,  Christopher  Seaman  (Sheriff) 

<Christopher.Seaman@cookcountyil.gov> 

Sent:  July  6,  2020  10:04:05  AM  CDT 

Received:  July  6,  2020  1 0:04:09  AM  CDT 


External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 


Attorney-Client  Privilege 


A  task  has  been  assigned  to  you  to  Provide  Records  on 
Request  FOIA  Request  /  #R009142-062920 
Activity  #4766 


Activity  Information 

Activity  Assigned  Staff:  Christopher  Seaman 
Activity  Type:  Provide  Employee  Records 
Due  Date:  7/13/2020 

Activity  Summary:  Please  let  me  know  what  is  returned  in  keyword  search  "BlueLeaks"  for  1 1/1/2018 
-  present 


FOIA  Request  for  Records 
Assigned  Staff:  Elizabeth  Scannell 
Status:  Received 
Create  Date:  June  29,  2020 
Due  Date:  July  06,  2020 
Name  of  Requester:  Emma  Best 
Requester  Affiliation:  Press 

Record(s)  Requested:  To  Whom  It  May  Concern:  Pursuant  to  the  Illinois  Freedom  of  Information  Act., 
I  hereby  request  the  following  records:  1.  Documents  mentioning,  describing  or  generated  in  response  to 
the  BlueLeaks  release,  the  preceding  hack  or  subsequent  fallout,  including  but  not  limited  to:  *  Damage 
assessments  *  Emails  *  Interagency  communications  (local,  state,  or  federal)  *  Communications  with 
the  press  about  BlueLeaks  *  Communications  with  Twitter  or  other  social  media  or  sharing  platforms  2. 
Documents  mentioning  or  describing  Distributed  Denial  of  Secrets  (DDoSecrets)  You  may  limit  this 
request  to  records  generated  between  November  1,  2018  and  the  present.  I  am  a  member  of  the  news 
media  and  request  classification  as  such.  I  have  previously  written  about  the  government  and  its 
activities,  with  some  reaching  over  100,000  readers  in  outlets  such  as  Gizmodo,  MuckRock, 
Motherboard,  Property  of  the  People,  Unicorn  Riot,  and  The  Outline,  among  others.  As  such,  as  I  have  a 
reasonable  expectation  of  publication  and  my  editorial  and  writing  skills  are  well  established.  In 


addition,  I  discuss  and  comment  on  the  files  online  and  make  them  available  through  non-profits  such  as 
the  library  Internet  Archive  and  the  journalist  non-profit  MuckRock,  disseminating  them  to  a  large 
audience.  While  my  research  is  not  limited  to  this,  a  great  deal  of  it,  including  this,  focuses  on  the 
activities  and  attitudes  of  the  government  itself.  As  such,  it  is  not  necessary  for  me  to  demonstrate  the 
relevance  of  this  particular  subject  in  advance.  As  my  primary  purpose  is  to  inform  about  government 
activities  by  reporting  on  it  and  making  the  raw  data  available,  I  request  that  fees  be  waived.  The 
requested  documents  will  be  made  available  to  the  general  public,  and  this  request  is  not  being  made  for 
commercial  purposes.  In  the  event  that  there  are  fees,  I  would  be  grateful  if  you  would  inform  me  of  the 
total  charges  in  advance  of  fulfilling  my  request.  I  would  prefer  the  request  filled  electronically,  by  e- 
mail  attachment  if  available  or  CD-ROM  if  not.  Thank  you  in  advance  for  your  anticipated  cooperation 
in  this  matter.  I  look  forward  to  receiving  your  response  to  this  request  within  5  business  days,  as  the 
statute  requires.  Sincerely,  Emma  Best  Upload  documents  directly: 

https://https://www.muckrock.comhttps://accounts.muckrock.com/accounts/login/?next=https%3A%2F 

%2Fwww.muckrock.com%2Faccounts%2Flogin%2F%3Fnext%3D%252Faccounts%252Fagency_login 

%252Fcook-county-sheriff-719%252Fblueleaks-cook-county-sheriff- 

9694 1  %252F%253F&url_auth_token=AAAaaJnszUYssmdgx6fh2R- 

tE3U%3AljppAE%3ADWZbgy7n8640ATjAMxtAsPZltYs 


This  is  an  auto-generated  email  and  has  originated  from  an  unmonitored  email  account.  Please  DO  NOT  REPLY  to  this  email  as  the 
contents  of  your  response  and  any  attachments  may  be  externally  disseminated  inadvertently.  Click  the  link  above  to  respond  and  upload 
documents  for  secure  internal  review. 


GovQA]  FOIA  Request  -  Activity  Assignment  — ::  R0091 42-062920  -  4766 

To:  Christopher  Seaman  (Sheriff) 

Sent:  July  6,  2020  1 0:04:05  AM  CDT 

Received:  July  6,  2020  1 0:04:09  AM  CDT 


RE:  FOIA 


From:  Elizabeth  Scannell  (Sheriff)  <Elizabeth. Scannell@cookcountyil.gov> 

To:  Helen  Burke  (Sheriff)  <Helen.Burke@cookcountyil.gov>,  Nicholas  Scouffas 

(Sheriff)  <Nicholas.Scouffas@cookcountyil.gov>,  Amar  Patel  (Sheriff) 
<Amar.Patel@cookcountyil.gov>,  Eryn  Hedderman  (Sheriff) 
<Eryn.Hedderman@cookcountyil.gov>,  Matthew  Walberg  (Sheriff) 
<Matthew.Walberg@cookcountyil.gov>,  Breeann  Rials  (Sheriff) 

<  breea  nn .  rials@cookcou  nty  i  I  .gov> 

Cc:  Joseph  Ryan  (Sheriff)  <Joseph.Ryan2@cookcountyil.gov>,  Jacquelyn 

Hedderman  (Sheriff)  <Jacquelyn.Hedderman@cookcountyil.gov>,  Bradley 
Curry  (Sheriff)  <Bradley.Curry@cookcountyil.gov>,  Kathleen  Carmody 
(Sheriff)  <Kathleen.Carmody@cookcountyil.gov> 

Sent:  July  7,  2020  1 0:57:55  AM  CDT 

Received:  July  7,  2020  1 0:57:56  AM  CDT 

Attachments:  Agenda  FOIA  Meeting  for  7.7-20.pdf 

See  attached  for  our  call, 

Beth  Scannell 
Assistant  General  Counsel 

Cook  County  Sheriff's  Office 
50  W.  Washington,  Room  704 
Chicago,  Illinois  60602 
Desk:  312.603.3979 
Mobile:  312.515.5170 

The  contents  of  this  e-mail  message  and  any  attachments  are  intended  solely  for  the  addressee(s)  named  in  this  message.  This  communication 
is  intended  to  be  and  to  remain  confidential  and  may  be  subject  to  applicable  attorney-client  and/or  work  product  privileges.  If  you  are  not  the 
intended  recipient  of  this  message  or  if  this  message  has  been  addressed  to  you  in  error,  please  alert  the  sender  immediately  by  reply  e-mail 
and  then  delete  this  message  and  its  attachments.  Do  not  deliver,  distribute  or  copy  this  message  and/or  any  attachments  and  if  you  are  not 
the  intended  recipient,  do  not  disclose  the  contents  or  take  any  action  in  reliance  upon  the  information  contained  in  this  communication  or 
any  attachments.  Thank  you. 


- Original  Appointment - 

From:  Helen  Burke  (Sheriff)  <Helen.Burke@cookcountyil.gov> 

Sent:  Tuesday,  March  19,  2019  2:48  PM 

To:  Helen  Burke  (Sheriff);  Nicholas  Scouffas  (Sheriff);  Elizabeth  Scannell  (Sheriff);  Amar  Patel  (Sheriff);  Eryn 
Hedderman  (Sheriff);  Matthew  Walberg  (Sheriff);  Breeann  Rials  (Sheriff) 

Cc:  Joseph  Ryan  (Sheriff);  Jacquelyn  Hedderman  (Sheriff);  Bradley  Curry  (Sheriff);  Kathleen  Carmody  (Sheriff) 
Subject:  FOIA 

When:  Tuesday,  July  7,  2020  11:30  AM-12:00  PM  (UTC-06:00)  Central  Time  (US  &  Canada). 

Where:  Dial-in  number:  515-604-9587;  Access  code:  711450 

UPDATE:  This  call  has  been  moved  to  Tuesday  7/7  at  11:30 

Dial-in  number:  515-604-9587 

Access  code:  711450 


(Beth  will  host) 


RE:  FOIA 

To: 


Cc: 


Sent: 

Received: 


Helen  Burke  (Sheriff),  Nicholas  Scouffas  (Sheriff),  Amar  Patel  (Sheriff),  Eryn 
Hedderman  (Sheriff),  Matthew  Walberg  (Sheriff),  Breeann  Rials  (Sheriff),  Abraham 
Yasin  (Sheriff),  Tarry  Williams  (Sheriff),  Leo  Schmitz  (Sheriff),  Adriana  Morales 
(Sheriff),  Alfonzo  Hunter  (Sheriff),  Amanda  Gallegos  (Sheriff),  Bradley  Curry  (Sheriff), 
Brian  White  (Sheriff),  Carmen  Gercone  (Sheriff),  Carmen  Ruffin  (Sheriff),  Christopher 
Imhof  (Sheriff),  David  Chiko  (Sheriff),  Erik  Roedel  (Sheriff),  Gregory  Ernst  (Sheriff), 
Heather  Bock  (Sheriff),  Jennifer  Black  (Sheriff),  Jerry  Baldwin  (Sheriff),  John  Vega 
(Sheriff),  John  Webb  (Sheriff),  Jonathan  Myslinski  (Sheriff),  Joseph  Bellettiere  (Sheriff), 
Kathleen  Urbanczyk  (Sheriff),  Kelley  Eldridge  (Sheriff),  Kevin  Connelly  (Sheriff),  Kevin 
Ruel  (Sheriff),  Larry  Schurig  (Sheriff),  Lonnie  Hollis  (Sheriff),  Marlon  Parks  (Sheriff), 
Matthew  Creen  (Sheriff),  Michael  Brady  (Sheriff),  Michael  Lucente  (Sheriff),  Michael 
Miller  (Sheriff),  Patrick  Dwyer  (Sheriff),  Patrick  Moerlien  (Sheriff),  Richard  Brogan 
(Sheriff),  Richard  O'Brien  (Sheriff),  Robert  Lunk  (Sheriff),  Ronald  Jenkins  (Sheriff), 
Stephen  Bouffard  (Sheriff),  Theodore  Stajura  (Sheriff),  Jason  Hernandez  (Sheriff), 
James  Moore  (Sheriff),  Sheriff  Intel,  Arunas  Buntinas  (Sheriff),  Keith  Morrison  (Sheriff), 
Adnan  Memon  (Sheriff),  Douglas  Maclean  (Sheriff) 

Joseph  Ryan  (Sheriff),  Jacquelyn  Hedderman  (Sheriff),  Bradley  Curry  (Sheriff), 
Kathleen  Carmody  (Sheriff),  Adnan  Memon  (Sheriff),  Douglas  Maclean  (Sheriff), 

Marlon  Parks  (Sheriff),  Brian  White  (Sheriff),  Arunas  Buntinas  (Sheriff),  Tarry  Williams 
(Sheriff),  Amar  Patel  (Sheriff) 

July  7,  2020  10:57:55  AM  CDT 
July  7,  2020  10:57:56  AM  CDT 


RE:  FOIA 


To:  Helen  Burke  (Sheriff),  Nicholas  Scouffas  (Sheriff),  Amar  Patel  (Sheriff),  Eryn 

Hedderman  (Sheriff),  Matthew  Walberg  (Sheriff),  Breeann  Rials  (Sheriff) 

Cc:  Joseph  Ryan  (Sheriff),  Jacquelyn  Hedderman  (Sheriff),  Bradley  Curry  (Sheriff), 

Kathleen  Carmody  (Sheriff) 

Sent:  July  7,  2020  1 0:57:55  AM  CDT 

Received:  July  7,  2020  1 0:58:01  AM  CDT 


RE:  FOIA 


From:  Elizabeth  Scannell  (Sheriff)  </0=EXCHANGELABS/OU=EXCHANGE  ADMINISTRATIVE 

GROUP 

(FYDIBOHF23SPDLT)/CN=RECIPIENTS/CN=E3F5ADF1BBDC48C9BD4A9BE8268EA25 
E-ELIZABETH  S> 

To:  Helen  Burke  (Sheriff)  <Helen.Burke@cookcountyil.gov>,  Nicholas  Scouffas  (Sheriff) 

<Nicholas.Scouffas@cookcountyil.gov>,  Amar  Patel  (Sheriff) 
<Amar.Patel@cookcountyil.gov>,  Eryn  Hedderman  (Sheriff) 
<Eryn.Hedderman@cookcountyil.gov>,  Matthew  Walberg  (Sheriff) 
<Matthew.Walberg@cookcountyil.gov>,  Breeann  Rials  (Sheriff) 
<breeann.rials@cookcountyil.gov> 

Cc:  Joseph  Ryan  (Sheriff)  <Joseph.Ryan2@cookcountyil.gov>,  Jacquelyn  Hedderman  (Sheriff) 

< Jacquelyn. Hedderman@cookcountyil.gov>,  Bradley  Curry  (Sheriff) 
<Bradley.Curry@cookcountyil.gov>,  Kathleen  Carmody  (Sheriff) 
<Kathleen.Carmody@cookcountyil.gov> 

Sent:  July  7,  2020  10:57:55  AM  CDT 

Received:  July  7,  2020  1 0:57:00  AM  CDT 

Attachments:  Agenda  FOIA  Meeting  for  7. 7.20. pdf 

See  attached  for  our  call, 

Beth  Scannell 
Assistant  General  Counsel 

Cook  County  Sheriff's  Office 
50  W.  Washington,  Room  704 
Chicago,  Illinois  60602 
Desk:  312.603.3979 
Mobile:  312.515.5170 

The  contents  of  this  e-mail  message  and  any  attachments  are  intended  solely  for  the  addressee(s)  named  in  this  message.  This  communication 
is  intended  to  be  and  to  remain  confidential  and  may  be  subject  to  applicable  attorney-client  and/or  work  product  privileges.  If  you  are  not  the 
intended  recipient  of  this  message  or  if  this  message  has  been  addressed  to  you  in  error,  please  alert  the  sender  immediately  by  reply  e-mail 
and  then  delete  this  message  and  its  attachments.  Do  not  deliver,  distribute  or  copy  this  message  and/or  any  attachments  and  if  you  are  not 
the  intended  recipient,  do  not  disclose  the  contents  or  take  any  action  in  reliance  upon  the  information  contained  in  this  communication  or 
any  attachments.  Thank  you. 


- Original  Appointment - 

From:  Helen  Burke  (Sheriff)  <Helen.Burke@cookcountyil.gov> 

Sent:  Tuesday,  March  19,  2019  2:48  PM 

To:  Helen  Burke  (Sheriff);  Nicholas  Scouffas  (Sheriff);  Elizabeth  Scannell  (Sheriff);  Amar  Patel  (Sheriff);  Eryn 
Hedderman  (Sheriff);  Matthew  Walberg  (Sheriff);  Breeann  Rials  (Sheriff) 

Cc:  Joseph  Ryan  (Sheriff);  Jacquelyn  Hedderman  (Sheriff);  Bradley  Curry  (Sheriff);  Kathleen  Carmody  (Sheriff) 
Subject:  FOIA 

When:  Tuesday,  July  7,  2020  11:30  AM-12:00  PM  (UTC-06:00)  Central  Time  (US  &  Canada). 

Where:  Dial-in  number:  515-604-9587;  Access  code:  711450 

UPDATE:  This  call  has  been  moved  to  Tuesday  7/7  at  11:30 

Dial-in  number:  515-604-9587 

Access  code:  711450 


(Beth  will  host) 


IT  Security  News  Blast  -  7-8-2020 

From:  Mike  Hamilton  <Michael.Hamilton@CI.Security> 

To:  Keith.Morrison@cookcountyil.gov,  Keith  Morrison  (Sheriff) 

<Keith.Morrison@cookcountyil.gov> 

Sent:  July  8,  2020  7:14:13  AM  CDT 

Received:  July  8,  2020  7:14:21  AM  CDT 


External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 
opening  attachments,  clicking  links,  or  responding  to  this  email. 


Cyber  Command  urges  orgs  to  implement  F5  patch  for  BIG-IP  configuration 
interface  flaw 

U.S.  Cyber  Command  retweeted  last  Friday  F5’s  advisory  to  patch  immediately  the 
flaw  that  could  unleash  a  Remote  Code  Execution  (RCE),  possibly  leading  to  the 
creation  or  deletion  files,  disability  of  services,  interception  of  information,  run 
arbitrary  system  commands  and  Java  code,  completely  compromise  the  system,  and 
pursue  further  targets,  such  as  the  internal  network. 

https://www.scmagazine.com/home/securitv-news/cvber-command-urges-orgs-to- 

implement-f5-patch-for-big-ip-configuration-interface-flaw/ 


You  may  be  distracted  by  the  pandemic  but  FYI:  US  Senate  panel  OK's 
backdoors-by-the-backdoor  EARN  IT  Act 

The  idea  is  that  companies  would  have  to  “earn”  their  legal  shield  -  hence  the  name 
of  the  bill,  EARN  IT  -  by  following  the  best  practices  created  by  the  committee. 
Following  significant  pushback  on  those  points,  the  Judiciary  Committee  made 


changes  aimed  at  gaining  the  full  approval  of  all  its  members.  In  the  now-OK'd 
version  of  the  bill,  the  commission,  called  the  National  Commission  on  Online  Child 
Sexual  Exploitation  Prevention,  would  still  create  its  rules  but  it  would  be  “voluntary” 
for  online  platforms  to  follow  them.  Instead,  if  tech  companies  did  follow  the 
commission’s  rules,  it  “would  be  a  defense  in  any  civil  suit,”  said  committee  chair 
Lindsay  Graham  (R-SC). 

https://www.theregister.com/2020/07/06/revised  earn  it  act/ 


'If  the  public  knew:'  Ripple20  shows  medical  device  software  cyber  weakness 

The  stakes  are  high.  Last  month,  researchers  discovered  vulnerabilities  in  a  popular 
TCP/IP  library  from  a  third-party  software  vendor  Treck  used  by  Baxter  and  B.  Braun 
infusion  pumps,  potentially  allowing  hackers  to  take  control  of  the  devices  remotely 
and  alter  medication  dosages.  Baxter  downplayed  the  threat  calling  it  low-risk  or 
"controlled,"  as  defined  by  the  FDA's  cybersecurity  guidance,  while  B.  Braun  said  it  is 
working  to  patch  the  vulnerable  source  code. 

https://www.medtechdive.com/news/ripple20-medical-device-cvbersecurity-software- 

bill-of-materials/581031/ 


IT  forensics  costs  post-cyberattack  spike  68%  year-over-year 

While  63%  of  the  cost  of  a  cyberattack  for  a  non-healthcare  policyholder  went 
towards  IT  forensics,  just  41  %  of  this  cost  was  dedicated  to  IT  forensics  for 
healthcare  clients.  Instead,  legal  costs  took  the  top  spot  at  48%  of  the  total 
cyberattack  bill  of  healthcare  clients.  [...]  “Right  now,  the  industry  is  experiencing  a 
big  surge  in  cases,  and  demand  for  IT  forensics  services  is  growing,”  he  said. 
Meanwhile,  there’s  also  a  limited  supply  of  firms  offering  these  services,  leading  to  a 
jump  in  the  bill  for  forensics  services  post-cyberattack. 

https://www.insurancebusinessmag.com/us/news/cvber/it-forensics-costs- 

postcvberattack-spike-68-vearovervear-227 1 20.aspx 


BEC  Busts  Take  Down  Multimillion-Dollar  Operations 

A  second  case  involves  Nigerian  national  Olalekan  Jacob  Ponle,  also  known  as  "Mr. 


Woodbery"  and  "Mark  Kain."  A  criminal  complaint  accuses  him  of  orchestrating  BEC 
schemes  to  defraud  US  companies,  which  led  to  attempted  or  actual  losses 
amounting  to  tens  of  millions  of  dollars.  One  Chicago  company  was  tricked  into 
sending  wire  transfers  totaling  $15.2  million. 

https://www.darkreadinq.com/attacks-breaches/bec-busts-take-down-multimillion- 

dollar-operations/d/d-id/1 338282 


Ransomware  attack  on  insurance  MSP  Xchanging  affects  clients 

Global  IT  services  and  solutions  provider  DXC  Technology  announced  over  the 
weekend  a  ransomware  attack  on  systems  from  its  Xchanging  subsidiary.  Xchanging 
is  known  as  a  managed  service  provider  for  businesses  in  the  insurance  industry  but 
its  list  of  customers  includes  companies  from  other  fields:  financial  services, 
aerospace  and  defense,  automotive,  education,  consumer  packaged  goods, 
healthcare,  manufacturing. 

https://www.bleepinqcomputer.com/news/security/ransomware-attack-on-insurance- 

msp-xchanging-affects-clients/ 


Mexico’s  Central  Bank  Thwarts  Cyber  Attack  on  Its  Website  [Subscription] 

The  central  bank’s  protection  protocols  kicked  in,  preventing  disruption  of  its  financial 
market  processes  and  payment  systems,  according  to  a  statement  by  the  bank 
known  as  Banxico.  The  attempt  comes  two  years  after  hackers  hijacked  Mexican 
financial  institutions’  connections  to  the  country’s  domestic  payment  transfer  system, 
operated  by  Banxico,  and  got  away  with  at  least  $15  million.  This  latest  attack  was 
merely  on  the  website  and  all  central  bank  information  and  that  of  other  financial 
institutions!.] 

https://news.bloomberglaw.com/privacv-and-data-security/mexicos-central-bank- 

thwarts-cyber-attack-on-its-website 


Defense  cuts,  cybersecurity  and  loT:  Five  Senate  NDAA  amendments  to  know 

1 .  Studying  cyber  exploitation 


2. 


Cleaner  audits 


3.  The  Internet  of  Things 

4.  CISA  strength 

5.  One  less  step  for  contractors 

https://federalnewsnetwork.com/defense-main/2020/Q7/defense-cuts-cvbersecuritv- 

and-iot-five-senate-ndaa-amendments-to-know/ 


Russian  Cyber  Gang  'Cosmic  Lynx'  Focuses  on  Email  Fraud 

With  the  exception  of  a  few  French  emails  sent  to  targets  in  France,  most  of  the 
group's  communications  are  written  in  English,  and  its  operators  know  their 
vocabulary  —  some  emails  contain  words  like  "accretive"  and  "synergistic,"  both 
used  in  their  proper  context.  In  fact,  the  writing  is  so  good  that  researchers  think  it 
may  be  possible  Cosmic  Lynx  is  hiring  people  to  translate  the  initial  emails  so  their 
English  is  nearly  perfect,  says  Crane  Hassold,  senior  director  of  threat  research  at 
Agari.  "When  you  look  at  a  Cosmic  Lynx  BEC  attack,  it  is  miles  beyond  what  we 
generally  see,"  he  says  of  the  group's  sophistication. 

https://www.darkreadinq.com/attacks-breaches/russian-cvber-qanq-cosmic-lvnx- 

focuses-on-email-fraud/d/d-id/1 338291 


FBI  chief  slams  Chinese  cyberattacks  against  U.S.  calling  it  ‘one  of  the  largest 
transfers  of  wealth  in  human  history’ 

“To  achieve  its  goals  and  surpass  America,  China  recognizes  it  needs  to  make  leaps 
in  cutting  edge  technology,  but  the  sad  fact  is  that  instead  of  engaging  in  the  hard 
slog  of  innovation,  China  often  steals  American  intellectual  property  and  then  uses  it 
to  compete  against  the  very  American  companies  it  victimizes,  in  effect,  cheating 
twice,”  he  said,  adding  that  the  Chinese  government  targets  “research  on  everything 
from  military  equipment  to  wind  turbines.” 


https://www.cnbc.com/2020/07/Q7/fbi-chief-slams-chinese-cvberattacks-aqainst-us- 

hudson-institute.html 


FBI  Opens  a  New  China-Related  Counterintelligence  Investigation  Every  10 
Hours,  Director  Says 

“China  is  engaged  in  a  whole-of-state  effort  to  become  the  world’s  only  superpower 
by  any  means  necessary,”  Wray  said.  “The  greatest  long-term  threat  to  our  nation’s 
information  and  intellectual  property,  and  to  our  economic  vitality,  is  the 
counterintelligence  and  economic  espionage  threat  from  China.  It’s  a  threat  to  our 
economic  security — and  by  extension,  to  our  national  security.” 

https://www.nextqov.com/cvbersecuritv/2020/Q7/fbi-opens-new-china-related- 

counterintelligence-investiqation-everv-10-hours-director-says/l  66706/ 


Linkedln  was  copying  every  keystroke  of  users  until  iOS  14  exposed  it 

The  snooping  tactics  of  Linkedln  were  discovered  because  of  the  iOS  14  beta’s 
Universal  clipboard  privacy  feature  that  instantly  detects  when  a  widget  or  app 
accesses  data  on  the  clipboard.  [...]  Apparently,  the  issue  is  caused  by  an  equality 
check  between  the  typed  content  and  the  clipboard  contents.  Berger  reiterated  in  his 
tweets  that  Linkedln  never  stores  or  transmits  clipboard  data,  and  a  fix  for  this 
problem  will  be  out  soon. 

https://www.hackread.com/linkedin-copyinq-user-kevstrokel-ios-14-exposed-it/ 


Cops  Seize  Server  that  Hosted  BlueLeaks,  DDoSecrets  Says 

Authorities  in  Germany  have  seized  a  server  used  by  the  organization  that  published 
a  trove  of  US  police  internal  documents  commonly  known  as  BlueLeaks,  according 
to  the  organization’s  founder.  [...]  DDoSecrets  has  recently  taken  WikiLeaks  mantle 
as  the  most  influential  leaking  organization  on  the  internet,  publishing  several  dumps 
such  as  data  stolen  from  the  Chilean  military,  and  Neo-Nazi  messages  exchanged 
on  the  chat  platform  Discord. 

https://www.vice.com/en  us/article/qi43xq/cops-seize-blueleaks-ddosecrets-server 


E-Verify’s  “SSN  Lock”  is  Nothing  of  the  Sort 

Lest  you  think  your  SSN  and  DOB  is  somehow  private  information,  you  should  know 
this  static  data  about  U.S.  residents  has  been  exposed  many  times  over  in  countless 


data  breaches,  and  in  any  case  these  digits  are  available  for  sale  on  most  Americans 
via  Dark  Web  sites  for  roughly  the  bitcoin  equivalent  of  a  fancy  caffeinated  drink  at 
Starbucks. 

https://krebsonsecuritv.com/2020/07/e-verifys-ssn-lock-is-nothing-of-the-sort/ 


The  death  of  remote  access  VPN 

The  problem  with  Remote  Access  VPN  is  that  they  are  no  longer  suitable  for  a 
mobile  workforce  with  rampant  and  unabating  cybersecurity  threats.  To  emphasize 
this  problem,  a  Gartner’s  June  2019  analysis  predicts  that  by  2023,  60%  of 
enterprises  will  phase  out  their  Remote  Access  VPN  in  favor  of  Zero-Trust  Network 
Access. 

https://www.techradar.com/news/the-death-of-remote-access-vpn 


Microsoft  Seizes  Domains  Used  in  COVID-19-Themed  Attacks 

The  US  District  Court  for  the  Eastern  District  of  Virginia  had  earlier  granted  the 
company  permission  to  seize  the  domains  after  Microsoft  had  filed  a  civil  complaint 
about  the  attacks  causing  it  "irreparable  and  ongoing  harm."  Tom  Burt,  Microsoft 
corporate  vice  president,  customer  security  and  trust,  today  likened  the  attacks  to  a 
form  of  business  email  compromise  that  targeted  customers  in  62  countries. 

https://www.darkreadinq.com/operations/microsoft-seizes-domains-used-in-covid-19- 

themed-attacks/d/d-id/1 338293 


Citrix  Bugs  Allow  Unauthenticated  Code  Injection,  Data  Theft 

Attacks  on  the  management  interface  of  the  products  could  result  in  system 
compromise  by  an  unauthenticated  user  on  the  management  network;  or  system 
compromise  through  cross-site  scripting  (XSS).  Attackers  could  also  create  a 
download  link  for  the  device  which,  if  downloaded  and  then  executed  by  an 
unauthenticated  user  on  the  management  network,  could  result  in  the  compromise  of 
a  local  computer. 

https://threatpost.com/citrix-buqs-allow-unauthenticated-code-iniection-data- 


theft/157214/ 


Microsoft  Launches  Free  Linux  Forensics  and  Rootkit  Malware  Detection 
Service 

Microsoft  has  announced  a  new  free-to-use  initiative  aimed  at  uncovering  forensic 
evidence  of  sabotage  on  Linux  systems,  including  rootkits  and  intrusive  malware  that 
may  otherwise  go  undetected.  The  cloud  offering,  dubbed  Project  Freta,  is  a 
snapshot-based  memory  forensic  mechanism  that  aims  to  provide  automated  full- 
system  volatile  memory  inspection  of  virtual  machine  (VM)  snapshots,  with 
capabilities  to  spot  malicious  software,  kernel  rootkits,  and  other  stealthy  malware 
techniques  such  as  process  hiding. 

https://thehackernews.com/2020/07/microsoft-linux-forensics-rootkit.html 


Exposed  dating  service  databases  leak  sensitive  info  on  romance-seekers 

Independent  VPN  review  site  WizCase  has  reported  finding  six  separate  dating  sites 
or  apps  that  each  potentially  compromised  thousands  of  users  due  to  improper  data 
storage.  According  to  WizCase  researchers,  the  vast  majority  of  the  affected 
accounts  belong  to  Japanese  dating  sites  Charincharin.net  and  kyuun-kyuun.com, 
which  share  the  same  database.  [...]  “Every  server  was  easily  accessible  via  the 
internet  and  not  password  protected,”  the  report  stated. 

https://www.scmagazine.com/home/securitv-news/database-security/exposed- 

datinq-service-databases-leak-sensitive-info-on-romance-seekers/ 
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Cyber  Command  urges  orgs  to  implement  F5  patch  for  BIG-IP  configuration 
interface  flaw 

U.S.  Cyber  Command  retweeted  last  Friday  F5’s  advisory  to  patch  immediately  the 
flaw  that  could  unleash  a  Remote  Code  Execution  (RCE),  possibly  leading  to  the 
creation  or  deletion  files,  disability  of  services,  interception  of  information,  run 
arbitrary  system  commands  and  Java  code,  completely  compromise  the  system,  and 
pursue  further  targets,  such  as  the  internal  network. 

https://www.scmagazine.com/home/securitv-news/cvber-command-urges-orgs-to- 

implement-f5-patch-for-big-ip-configuration-interface-flaw/ 


You  may  be  distracted  by  the  pandemic  but  FYI:  US  Senate  panel  OK's 
backdoors-by-the-backdoor  EARN  IT  Act 

The  idea  is  that  companies  would  have  to  “earn”  their  legal  shield  -  hence  the  name 
of  the  bill,  EARN  IT  -  by  following  the  best  practices  created  by  the  committee. 
Following  significant  pushback  on  those  points,  the  Judiciary  Committee  made 


changes  aimed  at  gaining  the  full  approval  of  all  its  members.  In  the  now-OK'd 
version  of  the  bill,  the  commission,  called  the  National  Commission  on  Online  Child 
Sexual  Exploitation  Prevention,  would  still  create  its  rules  but  it  would  be  “voluntary” 
for  online  platforms  to  follow  them.  Instead,  if  tech  companies  did  follow  the 
commission’s  rules,  it  “would  be  a  defense  in  any  civil  suit,”  said  committee  chair 
Lindsay  Graham  (R-SC). 

https://www.theregister.com/2020/07/06/revised  earn  it  act/ 


'If  the  public  knew:'  Ripple20  shows  medical  device  software  cyber  weakness 

The  stakes  are  high.  Last  month,  researchers  discovered  vulnerabilities  in  a  popular 
TCP/IP  library  from  a  third-party  software  vendor  Treck  used  by  Baxter  and  B.  Braun 
infusion  pumps,  potentially  allowing  hackers  to  take  control  of  the  devices  remotely 
and  alter  medication  dosages.  Baxter  downplayed  the  threat  calling  it  low-risk  or 
"controlled,"  as  defined  by  the  FDA's  cybersecurity  guidance,  while  B.  Braun  said  it  is 
working  to  patch  the  vulnerable  source  code. 

https://www.medtechdive.com/news/ripple20-medical-device-cvbersecurity-software- 

bill-of-materials/581031/ 


IT  forensics  costs  post-cyberattack  spike  68%  year-over-year 

While  63%  of  the  cost  of  a  cyberattack  for  a  non-healthcare  policyholder  went 
towards  IT  forensics,  just  41  %  of  this  cost  was  dedicated  to  IT  forensics  for 
healthcare  clients.  Instead,  legal  costs  took  the  top  spot  at  48%  of  the  total 
cyberattack  bill  of  healthcare  clients.  [...]  “Right  now,  the  industry  is  experiencing  a 
big  surge  in  cases,  and  demand  for  IT  forensics  services  is  growing,”  he  said. 
Meanwhile,  there’s  also  a  limited  supply  of  firms  offering  these  services,  leading  to  a 
jump  in  the  bill  for  forensics  services  post-cyberattack. 

https://www.insurancebusinessmag.com/us/news/cvber/it-forensics-costs- 

postcvberattack-spike-68-vearovervear-227 1 20.aspx 


BEC  Busts  Take  Down  Multimillion-Dollar  Operations 

A  second  case  involves  Nigerian  national  Olalekan  Jacob  Ponle,  also  known  as  "Mr. 


Woodbery"  and  "Mark  Kain."  A  criminal  complaint  accuses  him  of  orchestrating  BEC 
schemes  to  defraud  US  companies,  which  led  to  attempted  or  actual  losses 
amounting  to  tens  of  millions  of  dollars.  One  Chicago  company  was  tricked  into 
sending  wire  transfers  totaling  $15.2  million. 

https://www.darkreadinq.com/attacks-breaches/bec-busts-take-down-multimillion- 

dollar-operations/d/d-id/1 338282 


Ransomware  attack  on  insurance  MSP  Xchanging  affects  clients 

Global  IT  services  and  solutions  provider  DXC  Technology  announced  over  the 
weekend  a  ransomware  attack  on  systems  from  its  Xchanging  subsidiary.  Xchanging 
is  known  as  a  managed  service  provider  for  businesses  in  the  insurance  industry  but 
its  list  of  customers  includes  companies  from  other  fields:  financial  services, 
aerospace  and  defense,  automotive,  education,  consumer  packaged  goods, 
healthcare,  manufacturing. 

https://www.bleepinqcomputer.com/news/security/ransomware-attack-on-insurance- 

msp-xchanging-affects-clients/ 


Mexico’s  Central  Bank  Thwarts  Cyber  Attack  on  Its  Website  [Subscription] 

The  central  bank’s  protection  protocols  kicked  in,  preventing  disruption  of  its  financial 
market  processes  and  payment  systems,  according  to  a  statement  by  the  bank 
known  as  Banxico.  The  attempt  comes  two  years  after  hackers  hijacked  Mexican 
financial  institutions’  connections  to  the  country’s  domestic  payment  transfer  system, 
operated  by  Banxico,  and  got  away  with  at  least  $15  million.  This  latest  attack  was 
merely  on  the  website  and  all  central  bank  information  and  that  of  other  financial 
institutions!.] 

https://news.bloomberglaw.com/privacv-and-data-security/mexicos-central-bank- 

thwarts-cyber-attack-on-its-website 


Defense  cuts,  cybersecurity  and  loT:  Five  Senate  NDAA  amendments  to  know 

1 .  Studying  cyber  exploitation 


2. 


Cleaner  audits 


3.  The  Internet  of  Things 

4.  CISA  strength 

5.  One  less  step  for  contractors 

https://federalnewsnetwork.com/defense-main/2020/Q7/defense-cuts-cvbersecuritv- 

and-iot-five-senate-ndaa-amendments-to-know/ 


Russian  Cyber  Gang  'Cosmic  Lynx'  Focuses  on  Email  Fraud 

With  the  exception  of  a  few  French  emails  sent  to  targets  in  France,  most  of  the 
group's  communications  are  written  in  English,  and  its  operators  know  their 
vocabulary  —  some  emails  contain  words  like  "accretive"  and  "synergistic,"  both 
used  in  their  proper  context.  In  fact,  the  writing  is  so  good  that  researchers  think  it 
may  be  possible  Cosmic  Lynx  is  hiring  people  to  translate  the  initial  emails  so  their 
English  is  nearly  perfect,  says  Crane  Hassold,  senior  director  of  threat  research  at 
Agari.  "When  you  look  at  a  Cosmic  Lynx  BEC  attack,  it  is  miles  beyond  what  we 
generally  see,"  he  says  of  the  group's  sophistication. 

https://www.darkreadinq.com/attacks-breaches/russian-cvber-qanq-cosmic-lvnx- 

focuses-on-email-fraud/d/d-id/1 338291 


FBI  chief  slams  Chinese  cyberattacks  against  U.S.  calling  it  ‘one  of  the  largest 
transfers  of  wealth  in  human  history’ 

“To  achieve  its  goals  and  surpass  America,  China  recognizes  it  needs  to  make  leaps 
in  cutting  edge  technology,  but  the  sad  fact  is  that  instead  of  engaging  in  the  hard 
slog  of  innovation,  China  often  steals  American  intellectual  property  and  then  uses  it 
to  compete  against  the  very  American  companies  it  victimizes,  in  effect,  cheating 
twice,”  he  said,  adding  that  the  Chinese  government  targets  “research  on  everything 
from  military  equipment  to  wind  turbines.” 


https://www.cnbc.com/2020/07/Q7/fbi-chief-slams-chinese-cvberattacks-aqainst-us- 

hudson-institute.html 


FBI  Opens  a  New  China-Related  Counterintelligence  Investigation  Every  10 
Hours,  Director  Says 

“China  is  engaged  in  a  whole-of-state  effort  to  become  the  world’s  only  superpower 
by  any  means  necessary,”  Wray  said.  “The  greatest  long-term  threat  to  our  nation’s 
information  and  intellectual  property,  and  to  our  economic  vitality,  is  the 
counterintelligence  and  economic  espionage  threat  from  China.  It’s  a  threat  to  our 
economic  security — and  by  extension,  to  our  national  security.” 

https://www.nextqov.com/cvbersecuritv/2020/Q7/fbi-opens-new-china-related- 

counterintelligence-investiqation-everv-10-hours-director-says/l  66706/ 


Linkedln  was  copying  every  keystroke  of  users  until  iOS  14  exposed  it 

The  snooping  tactics  of  Linkedln  were  discovered  because  of  the  iOS  14  beta’s 
Universal  clipboard  privacy  feature  that  instantly  detects  when  a  widget  or  app 
accesses  data  on  the  clipboard.  [...]  Apparently,  the  issue  is  caused  by  an  equality 
check  between  the  typed  content  and  the  clipboard  contents.  Berger  reiterated  in  his 
tweets  that  Linkedln  never  stores  or  transmits  clipboard  data,  and  a  fix  for  this 
problem  will  be  out  soon. 

https://www.hackread.com/linkedin-copyinq-user-kevstrokel-ios-14-exposed-it/ 


Cops  Seize  Server  that  Hosted  BlueLeaks,  DDoSecrets  Says 

Authorities  in  Germany  have  seized  a  server  used  by  the  organization  that  published 
a  trove  of  US  police  internal  documents  commonly  known  as  BlueLeaks,  according 
to  the  organization’s  founder.  [...]  DDoSecrets  has  recently  taken  WikiLeaks  mantle 
as  the  most  influential  leaking  organization  on  the  internet,  publishing  several  dumps 
such  as  data  stolen  from  the  Chilean  military,  and  Neo-Nazi  messages  exchanged 
on  the  chat  platform  Discord. 

https://www.vice.com/en  us/article/qi43xq/cops-seize-blueleaks-ddosecrets-server 


E-Verify’s  “SSN  Lock”  is  Nothing  of  the  Sort 

Lest  you  think  your  SSN  and  DOB  is  somehow  private  information,  you  should  know 
this  static  data  about  U.S.  residents  has  been  exposed  many  times  over  in  countless 


data  breaches,  and  in  any  case  these  digits  are  available  for  sale  on  most  Americans 
via  Dark  Web  sites  for  roughly  the  bitcoin  equivalent  of  a  fancy  caffeinated  drink  at 
Starbucks. 

https://krebsonsecuritv.com/2020/07/e-verifys-ssn-lock-is-nothing-of-the-sort/ 


The  death  of  remote  access  VPN 

The  problem  with  Remote  Access  VPN  is  that  they  are  no  longer  suitable  for  a 
mobile  workforce  with  rampant  and  unabating  cybersecurity  threats.  To  emphasize 
this  problem,  a  Gartner’s  June  2019  analysis  predicts  that  by  2023,  60%  of 
enterprises  will  phase  out  their  Remote  Access  VPN  in  favor  of  Zero-Trust  Network 
Access. 

https://www.techradar.com/news/the-death-of-remote-access-vpn 


Microsoft  Seizes  Domains  Used  in  COVID-19-Themed  Attacks 

The  US  District  Court  for  the  Eastern  District  of  Virginia  had  earlier  granted  the 
company  permission  to  seize  the  domains  after  Microsoft  had  filed  a  civil  complaint 
about  the  attacks  causing  it  "irreparable  and  ongoing  harm."  Tom  Burt,  Microsoft 
corporate  vice  president,  customer  security  and  trust,  today  likened  the  attacks  to  a 
form  of  business  email  compromise  that  targeted  customers  in  62  countries. 

https://www.darkreadinq.com/operations/microsoft-seizes-domains-used-in-covid-19- 

themed-attacks/d/d-id/1 338293 


Citrix  Bugs  Allow  Unauthenticated  Code  Injection,  Data  Theft 

Attacks  on  the  management  interface  of  the  products  could  result  in  system 
compromise  by  an  unauthenticated  user  on  the  management  network;  or  system 
compromise  through  cross-site  scripting  (XSS).  Attackers  could  also  create  a 
download  link  for  the  device  which,  if  downloaded  and  then  executed  by  an 
unauthenticated  user  on  the  management  network,  could  result  in  the  compromise  of 
a  local  computer. 

https://threatpost.com/citrix-buqs-allow-unauthenticated-code-iniection-data- 


theft/157214/ 


Microsoft  Launches  Free  Linux  Forensics  and  Rootkit  Malware  Detection 
Service 

Microsoft  has  announced  a  new  free-to-use  initiative  aimed  at  uncovering  forensic 
evidence  of  sabotage  on  Linux  systems,  including  rootkits  and  intrusive  malware  that 
may  otherwise  go  undetected.  The  cloud  offering,  dubbed  Project  Freta,  is  a 
snapshot-based  memory  forensic  mechanism  that  aims  to  provide  automated  full- 
system  volatile  memory  inspection  of  virtual  machine  (VM)  snapshots,  with 
capabilities  to  spot  malicious  software,  kernel  rootkits,  and  other  stealthy  malware 
techniques  such  as  process  hiding. 

https://thehackernews.com/2020/07/microsoft-linux-forensics-rootkit.html 


Exposed  dating  service  databases  leak  sensitive  info  on  romance-seekers 

Independent  VPN  review  site  WizCase  has  reported  finding  six  separate  dating  sites 
or  apps  that  each  potentially  compromised  thousands  of  users  due  to  improper  data 
storage.  According  to  WizCase  researchers,  the  vast  majority  of  the  affected 
accounts  belong  to  Japanese  dating  sites  Charincharin.net  and  kyuun-kyuun.com, 
which  share  the  same  database.  [...]  “Every  server  was  easily  accessible  via  the 
internet  and  not  password  protected,”  the  report  stated. 

https://www.scmagazine.com/home/securitv-news/database-security/exposed- 

datinq-service-databases-leak-sensitive-info-on-romance-seekers/ 
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Greetings  Brian  White  Wednesday,  July  8,  2020 


POLICING  &  POLICY 


5ome  US  States  Consider  Police  Licensing 

Bloomberg  Law  (7/7,  Ebert,  Subscription  Publication)  reports, 
'Government  officials  in  at  least  a  half-dozen  states  want  to  make  it 
aasier  to  end  the  policing  careers  of  abusive  officers  by  making  it  hard 
■  For  them  to  start  fresh  in  new  jurisdictions.  'Now  is  the  time,  I  believe,  to 
Degin  treating  peace  officer  certificates  more  like  licenses,'  said  Ohio 
3ov.  Mike  DeWine.  'The  only  way  the  state  can  revoke  a  peace  officer 
certificate  today  is  if  that  officer  is  convicted  of  a  felony,'  he  said  in 
unveiling  a  proposal  to  beef  up  statewide  oversight  of  law  enforcement. 
There  is  no  mechanism  in  Ohio  to  revoke  a  certificate  for  conduct  that 
■night  be  bad,  might  be  horrible,  but  is  not  necessarily  criminal.'" 
3loomberg  Law  adds,  "Occupational  licensing  proposals  for  law 
enforcement  have  been  pitched  in  recent  weeks  in  California,  Illinois, 
Massachusetts,  New  Jersey,  Ohio,  and  Michigan.  Three  of  those  states  -  California,  Massachusetts,  and  New  Jersey  -  along  with 
Rhode  Island  lack  any  statewide  procedure  for  decertifying  officers." 

San  Diego,  California  To  Put  Police  Reform  Measure  On  November  Ballot 

The  San  Diego  Union-Tribune  (7/7,  Garrick)  reports,  "Critics  of  local  law  enforcement  got  a  key  win  Tuesday  when  the  San 
Diego  City  Council  unanimously  agreed  to  place  a  long-awaited  police  reform  measure  on  the  November  ballot."  According  to 
the  Union-Tribune,  "City  voters  will  get  a  chance  this  November  to  create  a  new  police  oversight  board  that  would  have  the 
power  to  launch  independent  misconduct  investigations,  subpoena  witnesses  and  hold  officers  more  accountable  for  their 


actions.  Community  leaders  and  council  members  said  Tuesday's  vote  was  an  important  milestone  that  would  allow  voters  to 
boost  transparency  and  accountability  for  local  police.  But  they  also  stressed  that  much  more  needs  to  be  done  on  police 
reform."  The  Union-Tribune  adds,  "Other  recent  reform  efforts  in  San  Diego  include  a  ban  on  police  officers  using  carotid 
restraints,  new  Police  Department  de-escalation  procedures  and  creation  of  an  Office  on  Race  and  Equity." 

US  House  Democrats  Include  $597  Million  For  Police  Reform  In  Spending  Bill 

The  Hill  (7/7,  Elis)  reports,  "House  Democrats  included  a  slew  of  police  reforms,  as  well  as  $596.7  million  in  funding  for 
reform  programs,  in  a  proposed  spending  bill  for  the  2021  fiscal  year,  which  begins  in  October."  The  Hill  adds,  "The  2021 
Commerce,  Justice,  Science  appropriations  bill  includes  $400  million  for  initiatives  that  would  boost  independent  investigations 
of  law  enforcement,  pattern  and  practice  investigations  that  look  for  systemic  problems  in  policing,  community-based 
organizations  seeking  to  improve  law  enforcement  and  other  initiatives.  It  would  also  provide  $50  million  to  train  local  law 
enforcement  on  certain  best  practices,  $77.5  million  to  grant  programs  to  boost  police-community  relations,  $25  million  for 
federal  investigations  into  misconduct  and  $4  million  for  civilian  review  boards." 

US  Lawmakers  Unveil  Bill  To  Defund  Police,  Provide  Reparations 

The  New  York  Post  (7/7,  Nelson)  reports  that  US  Reps.  Ayanna  Pressley  (D-MA)  and  Rashida  Tlaib  (D-MI)  on  Tuesday 
"announced  federal  legislation  to  defund  police  and  set  up  reparations  for  people  who  either  are  black  or  were  harmed  by 
cops."  The  two  lawmakers  announced  the  measure  "on  a  Zoom  call,"  but  it  "has  not  yet  been  introduced."  Said  Tlaib,  "We  can 
start  to  envision  through  this  bill  a  new  version  for  public  safety  -  a  new  vision  for  public  safety,  one  that  protects  and  affirms 
Black  lives." 

The  AP  (7/7,  Stafford)  reports,  "Dubbed  the  BREATHE  Act,  the  legislation  is  the  culmination  of  a  project  led  by  the 
policy  table  of  the  Movement  for  Black  Lives,  a  coalition  of  more  than  150  organizations." 

Minnesota  Lawmakers  Remain  Hopeful  About  Police  Reform  Efforts 

The  Minneapolis  StarTribune  (7/8,  Berkel,  Bierschbach)  reports,  "Minnesota  state  lawmakers  will  get  another  chance  at 
passing  police  accountability  measures  into  law  next  week,  with  Gov.  Tim  Walz  planning  to  call  a  special  legislative  session  for 
the  second  time  this  summer."  The  StarTribune  adds,  "Walz  said  Tuesday  he  is  optimistic  that  lawmakers  can  strike  a  deal  on 
both  a  public  works  spending  package  and  on  police  reforms  in  the  wake  of  the  May  death  of  George  Floyd  at  the  hands  of 
Minneapolis  police  officers."  House  Democrats  "continue  to  push  for  a  sweeping  package  of  changes  to  boost  community-led 
alternatives  to  policing,  ban  warrior-style  training  for  officers  and  raise  the  threshold  for  using  deadly  force  from  'apparent'  to 
'imminent'  threats  to  officers  and  others." 


For  U.S.  Members: 

The  2019-2020  Public  Safety  Officer  Medal  of  Valor  is  the  United  States'  highest  public  safety  honor  that  can  be 
awarded  to  law  enforcement  officers,  emergency  medical  personnel,  and  firefighters.  This  award  honors  federal, 
state,  local,  and  tribal  public  safety  officers  who  have  demonstrated  exceptional  bravery,  risking  serious  injury  or 
death,  in  the  line  of  duty.  The  Bureau  of  Justice  Assistance  is  seeking  nominations  for  the  Medal  of  Valor  now 
through  Friday,  July  31,  2020. 

Public  Safety  Officers  can  be  nominated  for  any  qualifying  event  between  June  1,  2019,  and  May  31,  2020.  Public 
Safety  Officers  must  be  nominated  by  the  heads  of  their  agencies  by  July  31,  2020,  at  11:59  p.m.  ET  to  be 
considered  for  this  award.  Agency  heads  may  submit  multiple  nominations  to  honor  several  officers  or  to  honor 
one  officer  for  multiple  separate  events.  Nomination  guidelines  and  stories  of  past  recipients  can  be  found  on 
the  Medal  of  Valor  website. 
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CRIME  &  DRUGS 


Black  Americans  Report  Hate  Crimes,  Violence  In  Wake  Of  Floyd  Protests 

USA  Today  (7/7,  Philimon)  reports  that  a  "range  of  disturbing  incidents  have  happened  since  George  Floyd's  death  and 
subsequent  protests  against  racism  and  police  brutality."  In  Illinois,  for  example,  "a  man  was  charged  with  a  hate  crime  for 
allegedly  riding  his  motorcycle  into  a  protest  and  hitting  two  people,"  and  "authorities  say  a  KKK  leader  tried  to  run  his  car 
through  a  group  of  peaceful  protesters  in  Virginia." 

The  Washington  Examiner  (7/7,  Smith),  meanwhile,  reports  that  "two  white  residents  of  Martinez,  California,  who 
painted  over  a  Black  Lives  Matter  mural,  have  been  charged  with  a  hate  crime." 

The  Wall  Street  Journal  (7/7,  Kusisto,  Frosch,  Subscription  Publication)  reports  Floyd's  death  has  also  prompted  the 
reexamination  of  older  cases  by  local  prosecutors. 

New  York  City  Police  Arrest  195  In  Fireworks  Crackdown 

WNBC-TV  New  York  (7/7)  reports,  "Nearly  200  illegal  fireworks  have  been  made  in  New  York  City  in  the  two  weeks  since 
Mayor  Bill  de  Blasio  unveiled  a  multi-agency  task  force  to  crack  down  on  the  problem  amid  an  unprecedented  level  of 
complaints,  officials  said  Tuesday."  WNBC-TV  adds,  "The  mayor  revealed  the  task  force,  comprised  of  10  officers  with  the  NYPD 
Intelligence  Bureau,  12  FDNY  Fire  Marshals  and  20  Sheriff's  Bureau  of  Criminal  Investigation  members,  on  June  23.  Its  primary 
goal:  to  disrupt  illegal  fireworks  supply  chains  via  sting  operations  within  and  outside  New  York  City  -  and  officials  say  the  group 
busted  a  total  of  195  people  since  it  was  established.  It's  not  clear  what  prompted  the  extraordinary  surge  in  illegal  fireworks 
usage,  which  prompted  sleep-deprived  New  Yorkers  to  protest  in  front  of  Gracie  Mansion  one  night  last  month  amid  continued 
booming." 

Protesters  Charged  With  Leaking  Police  Document  In  Iowa 

The  AP  (7/7,  Foley)  reports,  "Prosecutors  in  Iowa  have  filed  a  rarely  used  leak  charge  against  Black  Lives  Matter  protesters 
accused  of  stealing  a  confidential  police  document  and  displaying  it  during  a  television  news  broadcast."  The  AP  adds,  "Two 
protesters  are  charged  with  unauthorized  dissemination  of  intelligence  data,  a  felony  that  carries  up  to  five  years  in  prison.  The 
Iowa  Judicial  Branch  says  it's  only  the  second  time  that  the  charge  has  been  filed  since  2010.  It's  intended  to  punish  officers  and 
others  who  share  information  that  could  undermine  criminal  investigations  or  violate  privacy  protections."  According  to  the  AP, 
"The  document  in  question  was  a  Des  Moines  Police  Department  bulletin  that  officers  and  state  troopers  had  with  them  while 
patrolling  a  July  1  protest  at  the  Iowa  Capitol.  The  bulletin  included  photos  of  suspects  who  were  wanted  in  the  destruction  of  a 
Des  Moines  police  car  during  a  June  20  protest." 

Dutch  Police  Arrest  Six,  Uncover  Makeshift  Torture  Chamber 

The  AP  (7/7,  Corder)  reports,  "Dutch  police  arrested  six  men  after  discovering  sea  containers  that  had  been  converted 
into  a  makeshift  prison  and  sound-proofed  'torture  chamber'  complete  with  a  dentist's  chair,  tools  including  pliers  and  scalpels 
and  handcuffs,  a  high  ranking  officer  announced  Tuesday.  Authorities  said  police  conducted  the  raid  before  the  torture 
chamber  could  be  used  and  alerted  potential  victims,  who  went  into  hiding."  The  AP  adds,  "The  grisly  discovery  was  made  last 
month  by  officers  investigating  leads  generated  by  data  from  encrypted  phones  used  by  criminals.  The  communications 
network  was  cracked  recently  by  French  police.  Detectives  in  Britain  and  the  Netherlands  have  already  arrested  hundreds  of 
suspects  based  on  the  encrypted  messages."  According  to  the  AP,  "Tuesday's  announcement  gave  a  chilling  insight  into  the 
increasingly  violent  Dutch  criminal  underworld,  which  is  involved  in  the  large  scale  production  and  trafficking  of  drugs." 

TECHNOLOGY 

German  Authorities  Seize  Server  Hosting  "BlueLeaks"  Data  Dump 

PCMag  (7/7,  Kan)  reports,  "German  authorities  have  confiscated  a  server  hosting  the  "BlueLeaks"  data  dump,  a  269GB 
trove  of  internal  police  documents  that  leaked  last  month."  According  to  PCMag,  "The  Wikileaks-style  group  Distributed  Denial 


of  Secrets  (DDOS)  had  been  using  the  server  to  enable  the  public  to  download  the  files,  but  prosecutors  in  Germany  recently 
seized  it,  according  to  Emma  Best,  a  journalist  and  co-founder  of  the  group.  DDOS  says  it  obtained  the  files  from  the  'hacktivist' 
collective  Anonymous,  and  then  made  the  files  searchable  on  a  dedicated  website  on  July  19.  However,  the  site  now  appears  to 
be  down."  Best  said  "German  authorities  seized  the  'primary  public  download  server'  hosting  the  data  dump  without  supplying 
an  explanation.  The  hosting  provider  has  only  said  the  takedown  came  from  the  'department  of  public  prosecution  Zwickau,' 
which  didn't  immediately  respond  to  a  request  for  comment." 
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Greetings  Keith  Morrison  Wednesday,  July  8,  2020 


POLICING  &  POLICY 


5ome  US  States  Consider  Police  Licensing 

Bloomberg  Law  (7/7,  Ebert,  Subscription  Publication)  reports, 
'Government  officials  in  at  least  a  half-dozen  states  want  to  make  it 
aasier  to  end  the  policing  careers  of  abusive  officers  by  making  it  hard 
■  For  them  to  start  fresh  in  new  jurisdictions.  'Now  is  the  time,  I  believe,  to 
Degin  treating  peace  officer  certificates  more  like  licenses,'  said  Ohio 
3ov.  Mike  DeWine.  'The  only  way  the  state  can  revoke  a  peace  officer 
certificate  today  is  if  that  officer  is  convicted  of  a  felony,'  he  said  in 
unveiling  a  proposal  to  beef  up  statewide  oversight  of  law  enforcement. 
There  is  no  mechanism  in  Ohio  to  revoke  a  certificate  for  conduct  that 
■night  be  bad,  might  be  horrible,  but  is  not  necessarily  criminal.'" 
3loomberg  Law  adds,  "Occupational  licensing  proposals  for  law 
enforcement  have  been  pitched  in  recent  weeks  in  California,  Illinois, 
Massachusetts,  New  Jersey,  Ohio,  and  Michigan.  Three  of  those  states  -  California,  Massachusetts,  and  New  Jersey  -  along  with 
Rhode  Island  lack  any  statewide  procedure  for  decertifying  officers." 

San  Diego,  California  To  Put  Police  Reform  Measure  On  November  Ballot 

The  San  Diego  Union-Tribune  (7/7,  Garrick)  reports,  "Critics  of  local  law  enforcement  got  a  key  win  Tuesday  when  the  San 
Diego  City  Council  unanimously  agreed  to  place  a  long-awaited  police  reform  measure  on  the  November  ballot."  According  to 
the  Union-Tribune,  "City  voters  will  get  a  chance  this  November  to  create  a  new  police  oversight  board  that  would  have  the 
power  to  launch  independent  misconduct  investigations,  subpoena  witnesses  and  hold  officers  more  accountable  for  their 


actions.  Community  leaders  and  council  members  said  Tuesday's  vote  was  an  important  milestone  that  would  allow  voters  to 
boost  transparency  and  accountability  for  local  police.  But  they  also  stressed  that  much  more  needs  to  be  done  on  police 
reform."  The  Union-Tribune  adds,  "Other  recent  reform  efforts  in  San  Diego  include  a  ban  on  police  officers  using  carotid 
restraints,  new  Police  Department  de-escalation  procedures  and  creation  of  an  Office  on  Race  and  Equity." 

US  House  Democrats  Include  $597  Million  For  Police  Reform  In  Spending  Bill 

The  Hill  (7/7,  Elis)  reports,  "House  Democrats  included  a  slew  of  police  reforms,  as  well  as  $596.7  million  in  funding  for 
reform  programs,  in  a  proposed  spending  bill  for  the  2021  fiscal  year,  which  begins  in  October."  The  Hill  adds,  "The  2021 
Commerce,  Justice,  Science  appropriations  bill  includes  $400  million  for  initiatives  that  would  boost  independent  investigations 
of  law  enforcement,  pattern  and  practice  investigations  that  look  for  systemic  problems  in  policing,  community-based 
organizations  seeking  to  improve  law  enforcement  and  other  initiatives.  It  would  also  provide  $50  million  to  train  local  law 
enforcement  on  certain  best  practices,  $77.5  million  to  grant  programs  to  boost  police-community  relations,  $25  million  for 
federal  investigations  into  misconduct  and  $4  million  for  civilian  review  boards." 

US  Lawmakers  Unveil  Bill  To  Defund  Police,  Provide  Reparations 

The  New  York  Post  (7/7,  Nelson)  reports  that  US  Reps.  Ayanna  Pressley  (D-MA)  and  Rashida  Tlaib  (D-MI)  on  Tuesday 
"announced  federal  legislation  to  defund  police  and  set  up  reparations  for  people  who  either  are  black  or  were  harmed  by 
cops."  The  two  lawmakers  announced  the  measure  "on  a  Zoom  call,"  but  it  "has  not  yet  been  introduced."  Said  Tlaib,  "We  can 
start  to  envision  through  this  bill  a  new  version  for  public  safety  -  a  new  vision  for  public  safety,  one  that  protects  and  affirms 
Black  lives." 

The  AP  (7/7,  Stafford)  reports,  "Dubbed  the  BREATHE  Act,  the  legislation  is  the  culmination  of  a  project  led  by  the 
policy  table  of  the  Movement  for  Black  Lives,  a  coalition  of  more  than  150  organizations." 

Minnesota  Lawmakers  Remain  Hopeful  About  Police  Reform  Efforts 

The  Minneapolis  StarTribune  (7/8,  Berkel,  Bierschbach)  reports,  "Minnesota  state  lawmakers  will  get  another  chance  at 
passing  police  accountability  measures  into  law  next  week,  with  Gov.  Tim  Walz  planning  to  call  a  special  legislative  session  for 
the  second  time  this  summer."  The  StarTribune  adds,  "Walz  said  Tuesday  he  is  optimistic  that  lawmakers  can  strike  a  deal  on 
both  a  public  works  spending  package  and  on  police  reforms  in  the  wake  of  the  May  death  of  George  Floyd  at  the  hands  of 
Minneapolis  police  officers."  House  Democrats  "continue  to  push  for  a  sweeping  package  of  changes  to  boost  community-led 
alternatives  to  policing,  ban  warrior-style  training  for  officers  and  raise  the  threshold  for  using  deadly  force  from  'apparent'  to 
'imminent'  threats  to  officers  and  others." 


For  U.S.  Members: 

The  2019-2020  Public  Safety  Officer  Medal  of  Valor  is  the  United  States'  highest  public  safety  honor  that  can  be 
awarded  to  law  enforcement  officers,  emergency  medical  personnel,  and  firefighters.  This  award  honors  federal, 
state,  local,  and  tribal  public  safety  officers  who  have  demonstrated  exceptional  bravery,  risking  serious  injury  or 
death,  in  the  line  of  duty.  The  Bureau  of  Justice  Assistance  is  seeking  nominations  for  the  Medal  of  Valor  now 
through  Friday,  July  31,  2020. 

Public  Safety  Officers  can  be  nominated  for  any  qualifying  event  between  June  1,  2019,  and  May  31,  2020.  Public 
Safety  Officers  must  be  nominated  by  the  heads  of  their  agencies  by  July  31,  2020,  at  11:59  p.m.  ET  to  be 
considered  for  this  award.  Agency  heads  may  submit  multiple  nominations  to  honor  several  officers  or  to  honor 
one  officer  for  multiple  separate  events.  Nomination  guidelines  and  stories  of  past  recipients  can  be  found  on 
the  Medal  of  Valor  website. 
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Black  Americans  Report  Hate  Crimes,  Violence  In  Wake  Of  Floyd  Protests 

USA  Today  (7/7,  Philimon)  reports  that  a  "range  of  disturbing  incidents  have  happened  since  George  Floyd's  death  and 
subsequent  protests  against  racism  and  police  brutality."  In  Illinois,  for  example,  "a  man  was  charged  with  a  hate  crime  for 
allegedly  riding  his  motorcycle  into  a  protest  and  hitting  two  people,"  and  "authorities  say  a  KKK  leader  tried  to  run  his  car 
through  a  group  of  peaceful  protesters  in  Virginia." 

The  Washington  Examiner  (7/7,  Smith),  meanwhile,  reports  that  "two  white  residents  of  Martinez,  California,  who 
painted  over  a  Black  Lives  Matter  mural,  have  been  charged  with  a  hate  crime." 

The  Wall  Street  Journal  (7/7,  Kusisto,  Frosch,  Subscription  Publication)  reports  Floyd's  death  has  also  prompted  the 
reexamination  of  older  cases  by  local  prosecutors. 

New  York  City  Police  Arrest  195  In  Fireworks  Crackdown 

WNBC-TV  New  York  (7/7)  reports,  "Nearly  200  illegal  fireworks  have  been  made  in  New  York  City  in  the  two  weeks  since 
Mayor  Bill  de  Blasio  unveiled  a  multi-agency  task  force  to  crack  down  on  the  problem  amid  an  unprecedented  level  of 
complaints,  officials  said  Tuesday."  WNBC-TV  adds,  "The  mayor  revealed  the  task  force,  comprised  of  10  officers  with  the  NYPD 
Intelligence  Bureau,  12  FDNY  Fire  Marshals  and  20  Sheriff's  Bureau  of  Criminal  Investigation  members,  on  June  23.  Its  primary 
goal:  to  disrupt  illegal  fireworks  supply  chains  via  sting  operations  within  and  outside  New  York  City  -  and  officials  say  the  group 
busted  a  total  of  195  people  since  it  was  established.  It's  not  clear  what  prompted  the  extraordinary  surge  in  illegal  fireworks 
usage,  which  prompted  sleep-deprived  New  Yorkers  to  protest  in  front  of  Gracie  Mansion  one  night  last  month  amid  continued 
booming." 

Protesters  Charged  With  Leaking  Police  Document  In  Iowa 

The  AP  (7/7,  Foley)  reports,  "Prosecutors  in  Iowa  have  filed  a  rarely  used  leak  charge  against  Black  Lives  Matter  protesters 
accused  of  stealing  a  confidential  police  document  and  displaying  it  during  a  television  news  broadcast."  The  AP  adds,  "Two 
protesters  are  charged  with  unauthorized  dissemination  of  intelligence  data,  a  felony  that  carries  up  to  five  years  in  prison.  The 
Iowa  Judicial  Branch  says  it's  only  the  second  time  that  the  charge  has  been  filed  since  2010.  It's  intended  to  punish  officers  and 
others  who  share  information  that  could  undermine  criminal  investigations  or  violate  privacy  protections."  According  to  the  AP, 
"The  document  in  question  was  a  Des  Moines  Police  Department  bulletin  that  officers  and  state  troopers  had  with  them  while 
patrolling  a  July  1  protest  at  the  Iowa  Capitol.  The  bulletin  included  photos  of  suspects  who  were  wanted  in  the  destruction  of  a 
Des  Moines  police  car  during  a  June  20  protest." 

Dutch  Police  Arrest  Six,  Uncover  Makeshift  Torture  Chamber 

The  AP  (7/7,  Corder)  reports,  "Dutch  police  arrested  six  men  after  discovering  sea  containers  that  had  been  converted 
into  a  makeshift  prison  and  sound-proofed  'torture  chamber'  complete  with  a  dentist's  chair,  tools  including  pliers  and  scalpels 
and  handcuffs,  a  high  ranking  officer  announced  Tuesday.  Authorities  said  police  conducted  the  raid  before  the  torture 
chamber  could  be  used  and  alerted  potential  victims,  who  went  into  hiding."  The  AP  adds,  "The  grisly  discovery  was  made  last 
month  by  officers  investigating  leads  generated  by  data  from  encrypted  phones  used  by  criminals.  The  communications 
network  was  cracked  recently  by  French  police.  Detectives  in  Britain  and  the  Netherlands  have  already  arrested  hundreds  of 
suspects  based  on  the  encrypted  messages."  According  to  the  AP,  "Tuesday's  announcement  gave  a  chilling  insight  into  the 
increasingly  violent  Dutch  criminal  underworld,  which  is  involved  in  the  large  scale  production  and  trafficking  of  drugs." 

TECHNOLOGY 

German  Authorities  Seize  Server  Hosting  "BlueLeaks"  Data  Dump 

PCMag  (7/7,  Kan)  reports,  "German  authorities  have  confiscated  a  server  hosting  the  "BlueLeaks"  data  dump,  a  269GB 
trove  of  internal  police  documents  that  leaked  last  month."  According  to  PCMag,  "The  Wikileaks-style  group  Distributed  Denial 


of  Secrets  (DDOS)  had  been  using  the  server  to  enable  the  public  to  download  the  files,  but  prosecutors  in  Germany  recently 
seized  it,  according  to  Emma  Best,  a  journalist  and  co-founder  of  the  group.  DDOS  says  it  obtained  the  files  from  the  'hacktivist' 
collective  Anonymous,  and  then  made  the  files  searchable  on  a  dedicated  website  on  July  19.  However,  the  site  now  appears  to 
be  down."  Best  said  "German  authorities  seized  the  'primary  public  download  server'  hosting  the  data  dump  without  supplying 
an  explanation.  The  hosting  provider  has  only  said  the  takedown  came  from  the  'department  of  public  prosecution  Zwickau,' 
which  didn't  immediately  respond  to  a  request  for  comment." 
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Greetings  Jennifer  Warren  Wednesday,  July  8,  2020 


POLICING  &  POLICY 


5ome  US  States  Consider  Police  Licensing 

Bloomberg  Law  (7/7,  Ebert,  Subscription  Publication)  reports, 
'Government  officials  in  at  least  a  half-dozen  states  want  to  make  it 
aasier  to  end  the  policing  careers  of  abusive  officers  by  making  it  hard 
■  For  them  to  start  fresh  in  new  jurisdictions.  'Now  is  the  time,  I  believe,  to 
Degin  treating  peace  officer  certificates  more  like  licenses,'  said  Ohio 
3ov.  Mike  DeWine.  'The  only  way  the  state  can  revoke  a  peace  officer 
certificate  today  is  if  that  officer  is  convicted  of  a  felony,'  he  said  in 
unveiling  a  proposal  to  beef  up  statewide  oversight  of  law  enforcement. 
There  is  no  mechanism  in  Ohio  to  revoke  a  certificate  for  conduct  that 
■night  be  bad,  might  be  horrible,  but  is  not  necessarily  criminal.'" 
3loomberg  Law  adds,  "Occupational  licensing  proposals  for  law 
enforcement  have  been  pitched  in  recent  weeks  in  California,  Illinois, 
Massachusetts,  New  Jersey,  Ohio,  and  Michigan.  Three  of  those  states  -  California,  Massachusetts,  and  New  Jersey  -  along  with 
Rhode  Island  lack  any  statewide  procedure  for  decertifying  officers." 

San  Diego,  California  To  Put  Police  Reform  Measure  On  November  Ballot 

The  San  Diego  Union-Tribune  (7/7,  Garrick)  reports,  "Critics  of  local  law  enforcement  got  a  key  win  Tuesday  when  the  San 
Diego  City  Council  unanimously  agreed  to  place  a  long-awaited  police  reform  measure  on  the  November  ballot."  According  to 
the  Union-Tribune,  "City  voters  will  get  a  chance  this  November  to  create  a  new  police  oversight  board  that  would  have  the 
power  to  launch  independent  misconduct  investigations,  subpoena  witnesses  and  hold  officers  more  accountable  for  their 


actions.  Community  leaders  and  council  members  said  Tuesday's  vote  was  an  important  milestone  that  would  allow  voters  to 
boost  transparency  and  accountability  for  local  police.  But  they  also  stressed  that  much  more  needs  to  be  done  on  police 
reform."  The  Union-Tribune  adds,  "Other  recent  reform  efforts  in  San  Diego  include  a  ban  on  police  officers  using  carotid 
restraints,  new  Police  Department  de-escalation  procedures  and  creation  of  an  Office  on  Race  and  Equity." 

US  House  Democrats  Include  $597  Million  For  Police  Reform  In  Spending  Bill 

The  Hill  (7/7,  Elis)  reports,  "House  Democrats  included  a  slew  of  police  reforms,  as  well  as  $596.7  million  in  funding  for 
reform  programs,  in  a  proposed  spending  bill  for  the  2021  fiscal  year,  which  begins  in  October."  The  Hill  adds,  "The  2021 
Commerce,  Justice,  Science  appropriations  bill  includes  $400  million  for  initiatives  that  would  boost  independent  investigations 
of  law  enforcement,  pattern  and  practice  investigations  that  look  for  systemic  problems  in  policing,  community-based 
organizations  seeking  to  improve  law  enforcement  and  other  initiatives.  It  would  also  provide  $50  million  to  train  local  law 
enforcement  on  certain  best  practices,  $77.5  million  to  grant  programs  to  boost  police-community  relations,  $25  million  for 
federal  investigations  into  misconduct  and  $4  million  for  civilian  review  boards." 

US  Lawmakers  Unveil  Bill  To  Defund  Police,  Provide  Reparations 

The  New  York  Post  (7/7,  Nelson)  reports  that  US  Reps.  Ayanna  Pressley  (D-MA)  and  Rashida  Tlaib  (D-MI)  on  Tuesday 
"announced  federal  legislation  to  defund  police  and  set  up  reparations  for  people  who  either  are  black  or  were  harmed  by 
cops."  The  two  lawmakers  announced  the  measure  "on  a  Zoom  call,"  but  it  "has  not  yet  been  introduced."  Said  Tlaib,  "We  can 
start  to  envision  through  this  bill  a  new  version  for  public  safety  -  a  new  vision  for  public  safety,  one  that  protects  and  affirms 
Black  lives." 

The  AP  (7/7,  Stafford)  reports,  "Dubbed  the  BREATHE  Act,  the  legislation  is  the  culmination  of  a  project  led  by  the 
policy  table  of  the  Movement  for  Black  Lives,  a  coalition  of  more  than  150  organizations." 

Minnesota  Lawmakers  Remain  Hopeful  About  Police  Reform  Efforts 

The  Minneapolis  StarTribune  (7/8,  Berkel,  Bierschbach)  reports,  "Minnesota  state  lawmakers  will  get  another  chance  at 
passing  police  accountability  measures  into  law  next  week,  with  Gov.  Tim  Walz  planning  to  call  a  special  legislative  session  for 
the  second  time  this  summer."  The  StarTribune  adds,  "Walz  said  Tuesday  he  is  optimistic  that  lawmakers  can  strike  a  deal  on 
both  a  public  works  spending  package  and  on  police  reforms  in  the  wake  of  the  May  death  of  George  Floyd  at  the  hands  of 
Minneapolis  police  officers."  House  Democrats  "continue  to  push  for  a  sweeping  package  of  changes  to  boost  community-led 
alternatives  to  policing,  ban  warrior-style  training  for  officers  and  raise  the  threshold  for  using  deadly  force  from  'apparent'  to 
'imminent'  threats  to  officers  and  others." 


For  U.S.  Members: 

The  2019-2020  Public  Safety  Officer  Medal  of  Valor  is  the  United  States'  highest  public  safety  honor  that  can  be 
awarded  to  law  enforcement  officers,  emergency  medical  personnel,  and  firefighters.  This  award  honors  federal, 
state,  local,  and  tribal  public  safety  officers  who  have  demonstrated  exceptional  bravery,  risking  serious  injury  or 
death,  in  the  line  of  duty.  The  Bureau  of  Justice  Assistance  is  seeking  nominations  for  the  Medal  of  Valor  now 
through  Friday,  July  31,  2020. 

Public  Safety  Officers  can  be  nominated  for  any  qualifying  event  between  June  1,  2019,  and  May  31,  2020.  Public 
Safety  Officers  must  be  nominated  by  the  heads  of  their  agencies  by  July  31,  2020,  at  11:59  p.m.  ET  to  be 
considered  for  this  award.  Agency  heads  may  submit  multiple  nominations  to  honor  several  officers  or  to  honor 
one  officer  for  multiple  separate  events.  Nomination  guidelines  and  stories  of  past  recipients  can  be  found  on 
the  Medal  of  Valor  website. 
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CRIME  &  DRUGS 


Black  Americans  Report  Hate  Crimes,  Violence  In  Wake  Of  Floyd  Protests 

USA  Today  (7/7,  Philimon)  reports  that  a  "range  of  disturbing  incidents  have  happened  since  George  Floyd's  death  and 
subsequent  protests  against  racism  and  police  brutality."  In  Illinois,  for  example,  "a  man  was  charged  with  a  hate  crime  for 
allegedly  riding  his  motorcycle  into  a  protest  and  hitting  two  people,"  and  "authorities  say  a  KKK  leader  tried  to  run  his  car 
through  a  group  of  peaceful  protesters  in  Virginia." 

The  Washington  Examiner  (7/7,  Smith),  meanwhile,  reports  that  "two  white  residents  of  Martinez,  California,  who 
painted  over  a  Black  Lives  Matter  mural,  have  been  charged  with  a  hate  crime." 

The  Wall  Street  Journal  (7/7,  Kusisto,  Frosch,  Subscription  Publication)  reports  Floyd's  death  has  also  prompted  the 
reexamination  of  older  cases  by  local  prosecutors. 

New  York  City  Police  Arrest  195  In  Fireworks  Crackdown 

WNBC-TV  New  York  (7/7)  reports,  "Nearly  200  illegal  fireworks  have  been  made  in  New  York  City  in  the  two  weeks  since 
Mayor  Bill  de  Blasio  unveiled  a  multi-agency  task  force  to  crack  down  on  the  problem  amid  an  unprecedented  level  of 
complaints,  officials  said  Tuesday."  WNBC-TV  adds,  "The  mayor  revealed  the  task  force,  comprised  of  10  officers  with  the  NYPD 
Intelligence  Bureau,  12  FDNY  Fire  Marshals  and  20  Sheriff's  Bureau  of  Criminal  Investigation  members,  on  June  23.  Its  primary 
goal:  to  disrupt  illegal  fireworks  supply  chains  via  sting  operations  within  and  outside  New  York  City  -  and  officials  say  the  group 
busted  a  total  of  195  people  since  it  was  established.  It's  not  clear  what  prompted  the  extraordinary  surge  in  illegal  fireworks 
usage,  which  prompted  sleep-deprived  New  Yorkers  to  protest  in  front  of  Gracie  Mansion  one  night  last  month  amid  continued 
booming." 

Protesters  Charged  With  Leaking  Police  Document  In  Iowa 

The  AP  (7/7,  Foley)  reports,  "Prosecutors  in  Iowa  have  filed  a  rarely  used  leak  charge  against  Black  Lives  Matter  protesters 
accused  of  stealing  a  confidential  police  document  and  displaying  it  during  a  television  news  broadcast."  The  AP  adds,  "Two 
protesters  are  charged  with  unauthorized  dissemination  of  intelligence  data,  a  felony  that  carries  up  to  five  years  in  prison.  The 
Iowa  Judicial  Branch  says  it's  only  the  second  time  that  the  charge  has  been  filed  since  2010.  It's  intended  to  punish  officers  and 
others  who  share  information  that  could  undermine  criminal  investigations  or  violate  privacy  protections."  According  to  the  AP, 
"The  document  in  question  was  a  Des  Moines  Police  Department  bulletin  that  officers  and  state  troopers  had  with  them  while 
patrolling  a  July  1  protest  at  the  Iowa  Capitol.  The  bulletin  included  photos  of  suspects  who  were  wanted  in  the  destruction  of  a 
Des  Moines  police  car  during  a  June  20  protest." 

Dutch  Police  Arrest  Six,  Uncover  Makeshift  Torture  Chamber 

The  AP  (7/7,  Corder)  reports,  "Dutch  police  arrested  six  men  after  discovering  sea  containers  that  had  been  converted 
into  a  makeshift  prison  and  sound-proofed  'torture  chamber'  complete  with  a  dentist's  chair,  tools  including  pliers  and  scalpels 
and  handcuffs,  a  high  ranking  officer  announced  Tuesday.  Authorities  said  police  conducted  the  raid  before  the  torture 
chamber  could  be  used  and  alerted  potential  victims,  who  went  into  hiding."  The  AP  adds,  "The  grisly  discovery  was  made  last 
month  by  officers  investigating  leads  generated  by  data  from  encrypted  phones  used  by  criminals.  The  communications 
network  was  cracked  recently  by  French  police.  Detectives  in  Britain  and  the  Netherlands  have  already  arrested  hundreds  of 
suspects  based  on  the  encrypted  messages."  According  to  the  AP,  "Tuesday's  announcement  gave  a  chilling  insight  into  the 
increasingly  violent  Dutch  criminal  underworld,  which  is  involved  in  the  large  scale  production  and  trafficking  of  drugs." 

TECHNOLOGY 

German  Authorities  Seize  Server  Hosting  "BlueLeaks"  Data  Dump 

PCMag  (7/7,  Kan)  reports,  "German  authorities  have  confiscated  a  server  hosting  the  "BlueLeaks"  data  dump,  a  269GB 
trove  of  internal  police  documents  that  leaked  last  month."  According  to  PCMag,  "The  Wikileaks-style  group  Distributed  Denial 


of  Secrets  (DDOS)  had  been  using  the  server  to  enable  the  public  to  download  the  files,  but  prosecutors  in  Germany  recently 
seized  it,  according  to  Emma  Best,  a  journalist  and  co-founder  of  the  group.  DDOS  says  it  obtained  the  files  from  the  'hacktivist' 
collective  Anonymous,  and  then  made  the  files  searchable  on  a  dedicated  website  on  July  19.  However,  the  site  now  appears  to 
be  down."  Best  said  "German  authorities  seized  the  'primary  public  download  server'  hosting  the  data  dump  without  supplying 
an  explanation.  The  hosting  provider  has  only  said  the  takedown  came  from  the  'department  of  public  prosecution  Zwickau,' 
which  didn't  immediately  respond  to  a  request  for  comment." 
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Greetings  Noureen  Kapadia  Wednesday,  July  8,  2020 


POLICING  &  POLICY 


5ome  US  States  Consider  Police  Licensing 

Bloomberg  Law  (7/7,  Ebert,  Subscription  Publication)  reports, 
'Government  officials  in  at  least  a  half-dozen  states  want  to  make  it 
aasier  to  end  the  policing  careers  of  abusive  officers  by  making  it  hard 
■  For  them  to  start  fresh  in  new  jurisdictions.  'Now  is  the  time,  I  believe,  to 
Degin  treating  peace  officer  certificates  more  like  licenses,'  said  Ohio 
3ov.  Mike  DeWine.  'The  only  way  the  state  can  revoke  a  peace  officer 
certificate  today  is  if  that  officer  is  convicted  of  a  felony,'  he  said  in 
unveiling  a  proposal  to  beef  up  statewide  oversight  of  law  enforcement. 
There  is  no  mechanism  in  Ohio  to  revoke  a  certificate  for  conduct  that 
■night  be  bad,  might  be  horrible,  but  is  not  necessarily  criminal.'" 
3loomberg  Law  adds,  "Occupational  licensing  proposals  for  law 
enforcement  have  been  pitched  in  recent  weeks  in  California,  Illinois, 
Massachusetts,  New  Jersey,  Ohio,  and  Michigan.  Three  of  those  states  -  California,  Massachusetts,  and  New  Jersey  -  along  with 
Rhode  Island  lack  any  statewide  procedure  for  decertifying  officers." 

San  Diego,  California  To  Put  Police  Reform  Measure  On  November  Ballot 

The  San  Diego  Union-Tribune  (7/7,  Garrick)  reports,  "Critics  of  local  law  enforcement  got  a  key  win  Tuesday  when  the  San 
Diego  City  Council  unanimously  agreed  to  place  a  long-awaited  police  reform  measure  on  the  November  ballot."  According  to 
the  Union-Tribune,  "City  voters  will  get  a  chance  this  November  to  create  a  new  police  oversight  board  that  would  have  the 
power  to  launch  independent  misconduct  investigations,  subpoena  witnesses  and  hold  officers  more  accountable  for  their 


actions.  Community  leaders  and  council  members  said  Tuesday's  vote  was  an  important  milestone  that  would  allow  voters  to 
boost  transparency  and  accountability  for  local  police.  But  they  also  stressed  that  much  more  needs  to  be  done  on  police 
reform."  The  Union-Tribune  adds,  "Other  recent  reform  efforts  in  San  Diego  include  a  ban  on  police  officers  using  carotid 
restraints,  new  Police  Department  de-escalation  procedures  and  creation  of  an  Office  on  Race  and  Equity." 

US  House  Democrats  Include  $597  Million  For  Police  Reform  In  Spending  Bill 

The  Hill  (7/7,  Elis)  reports,  "House  Democrats  included  a  slew  of  police  reforms,  as  well  as  $596.7  million  in  funding  for 
reform  programs,  in  a  proposed  spending  bill  for  the  2021  fiscal  year,  which  begins  in  October."  The  Hill  adds,  "The  2021 
Commerce,  Justice,  Science  appropriations  bill  includes  $400  million  for  initiatives  that  would  boost  independent  investigations 
of  law  enforcement,  pattern  and  practice  investigations  that  look  for  systemic  problems  in  policing,  community-based 
organizations  seeking  to  improve  law  enforcement  and  other  initiatives.  It  would  also  provide  $50  million  to  train  local  law 
enforcement  on  certain  best  practices,  $77.5  million  to  grant  programs  to  boost  police-community  relations,  $25  million  for 
federal  investigations  into  misconduct  and  $4  million  for  civilian  review  boards." 

US  Lawmakers  Unveil  Bill  To  Defund  Police,  Provide  Reparations 

The  New  York  Post  (7/7,  Nelson)  reports  that  US  Reps.  Ayanna  Pressley  (D-MA)  and  Rashida  Tlaib  (D-MI)  on  Tuesday 
"announced  federal  legislation  to  defund  police  and  set  up  reparations  for  people  who  either  are  black  or  were  harmed  by 
cops."  The  two  lawmakers  announced  the  measure  "on  a  Zoom  call,"  but  it  "has  not  yet  been  introduced."  Said  Tlaib,  "We  can 
start  to  envision  through  this  bill  a  new  version  for  public  safety  -  a  new  vision  for  public  safety,  one  that  protects  and  affirms 
Black  lives." 

The  AP  (7/7,  Stafford)  reports,  "Dubbed  the  BREATHE  Act,  the  legislation  is  the  culmination  of  a  project  led  by  the 
policy  table  of  the  Movement  for  Black  Lives,  a  coalition  of  more  than  150  organizations." 

Minnesota  Lawmakers  Remain  Hopeful  About  Police  Reform  Efforts 

The  Minneapolis  StarTribune  (7/8,  Berkel,  Bierschbach)  reports,  "Minnesota  state  lawmakers  will  get  another  chance  at 
passing  police  accountability  measures  into  law  next  week,  with  Gov.  Tim  Walz  planning  to  call  a  special  legislative  session  for 
the  second  time  this  summer."  The  StarTribune  adds,  "Walz  said  Tuesday  he  is  optimistic  that  lawmakers  can  strike  a  deal  on 
both  a  public  works  spending  package  and  on  police  reforms  in  the  wake  of  the  May  death  of  George  Floyd  at  the  hands  of 
Minneapolis  police  officers."  House  Democrats  "continue  to  push  for  a  sweeping  package  of  changes  to  boost  community-led 
alternatives  to  policing,  ban  warrior-style  training  for  officers  and  raise  the  threshold  for  using  deadly  force  from  'apparent'  to 
'imminent'  threats  to  officers  and  others." 


For  U.S.  Members: 

The  2019-2020  Public  Safety  Officer  Medal  of  Valor  is  the  United  States'  highest  public  safety  honor  that  can  be 
awarded  to  law  enforcement  officers,  emergency  medical  personnel,  and  firefighters.  This  award  honors  federal, 
state,  local,  and  tribal  public  safety  officers  who  have  demonstrated  exceptional  bravery,  risking  serious  injury  or 
death,  in  the  line  of  duty.  The  Bureau  of  Justice  Assistance  is  seeking  nominations  for  the  Medal  of  Valor  now 
through  Friday,  July  31,  2020. 

Public  Safety  Officers  can  be  nominated  for  any  qualifying  event  between  June  1,  2019,  and  May  31,  2020.  Public 
Safety  Officers  must  be  nominated  by  the  heads  of  their  agencies  by  July  31,  2020,  at  11:59  p.m.  ET  to  be 
considered  for  this  award.  Agency  heads  may  submit  multiple  nominations  to  honor  several  officers  or  to  honor 
one  officer  for  multiple  separate  events.  Nomination  guidelines  and  stories  of  past  recipients  can  be  found  on 
the  Medal  of  Valor  website. 
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CRIME  &  DRUGS 


Black  Americans  Report  Hate  Crimes,  Violence  In  Wake  Of  Floyd  Protests 

USA  Today  (7/7,  Philimon)  reports  that  a  "range  of  disturbing  incidents  have  happened  since  George  Floyd's  death  and 
subsequent  protests  against  racism  and  police  brutality."  In  Illinois,  for  example,  "a  man  was  charged  with  a  hate  crime  for 
allegedly  riding  his  motorcycle  into  a  protest  and  hitting  two  people,"  and  "authorities  say  a  KKK  leader  tried  to  run  his  car 
through  a  group  of  peaceful  protesters  in  Virginia." 

The  Washington  Examiner  (7/7,  Smith),  meanwhile,  reports  that  "two  white  residents  of  Martinez,  California,  who 
painted  over  a  Black  Lives  Matter  mural,  have  been  charged  with  a  hate  crime." 

The  Wall  Street  Journal  (7/7,  Kusisto,  Frosch,  Subscription  Publication)  reports  Floyd's  death  has  also  prompted  the 
reexamination  of  older  cases  by  local  prosecutors. 

New  York  City  Police  Arrest  195  In  Fireworks  Crackdown 

WNBC-TV  New  York  (7/7)  reports,  "Nearly  200  illegal  fireworks  have  been  made  in  New  York  City  in  the  two  weeks  since 
Mayor  Bill  de  Blasio  unveiled  a  multi-agency  task  force  to  crack  down  on  the  problem  amid  an  unprecedented  level  of 
complaints,  officials  said  Tuesday."  WNBC-TV  adds,  "The  mayor  revealed  the  task  force,  comprised  of  10  officers  with  the  NYPD 
Intelligence  Bureau,  12  FDNY  Fire  Marshals  and  20  Sheriff's  Bureau  of  Criminal  Investigation  members,  on  June  23.  Its  primary 
goal:  to  disrupt  illegal  fireworks  supply  chains  via  sting  operations  within  and  outside  New  York  City  -  and  officials  say  the  group 
busted  a  total  of  195  people  since  it  was  established.  It's  not  clear  what  prompted  the  extraordinary  surge  in  illegal  fireworks 
usage,  which  prompted  sleep-deprived  New  Yorkers  to  protest  in  front  of  Gracie  Mansion  one  night  last  month  amid  continued 
booming." 

Protesters  Charged  With  Leaking  Police  Document  In  Iowa 

The  AP  (7/7,  Foley)  reports,  "Prosecutors  in  Iowa  have  filed  a  rarely  used  leak  charge  against  Black  Lives  Matter  protesters 
accused  of  stealing  a  confidential  police  document  and  displaying  it  during  a  television  news  broadcast."  The  AP  adds,  "Two 
protesters  are  charged  with  unauthorized  dissemination  of  intelligence  data,  a  felony  that  carries  up  to  five  years  in  prison.  The 
Iowa  Judicial  Branch  says  it's  only  the  second  time  that  the  charge  has  been  filed  since  2010.  It's  intended  to  punish  officers  and 
others  who  share  information  that  could  undermine  criminal  investigations  or  violate  privacy  protections."  According  to  the  AP, 
"The  document  in  question  was  a  Des  Moines  Police  Department  bulletin  that  officers  and  state  troopers  had  with  them  while 
patrolling  a  July  1  protest  at  the  Iowa  Capitol.  The  bulletin  included  photos  of  suspects  who  were  wanted  in  the  destruction  of  a 
Des  Moines  police  car  during  a  June  20  protest." 

Dutch  Police  Arrest  Six,  Uncover  Makeshift  Torture  Chamber 

The  AP  (7/7,  Corder)  reports,  "Dutch  police  arrested  six  men  after  discovering  sea  containers  that  had  been  converted 
into  a  makeshift  prison  and  sound-proofed  'torture  chamber'  complete  with  a  dentist's  chair,  tools  including  pliers  and  scalpels 
and  handcuffs,  a  high  ranking  officer  announced  Tuesday.  Authorities  said  police  conducted  the  raid  before  the  torture 
chamber  could  be  used  and  alerted  potential  victims,  who  went  into  hiding."  The  AP  adds,  "The  grisly  discovery  was  made  last 
month  by  officers  investigating  leads  generated  by  data  from  encrypted  phones  used  by  criminals.  The  communications 
network  was  cracked  recently  by  French  police.  Detectives  in  Britain  and  the  Netherlands  have  already  arrested  hundreds  of 
suspects  based  on  the  encrypted  messages."  According  to  the  AP,  "Tuesday's  announcement  gave  a  chilling  insight  into  the 
increasingly  violent  Dutch  criminal  underworld,  which  is  involved  in  the  large  scale  production  and  trafficking  of  drugs." 

TECHNOLOGY 

German  Authorities  Seize  Server  Hosting  "BlueLeaks"  Data  Dump 

PCMag  (7/7,  Kan)  reports,  "German  authorities  have  confiscated  a  server  hosting  the  "BlueLeaks"  data  dump,  a  269GB 
trove  of  internal  police  documents  that  leaked  last  month."  According  to  PCMag,  "The  Wikileaks-style  group  Distributed  Denial 


of  Secrets  (DDOS)  had  been  using  the  server  to  enable  the  public  to  download  the  files,  but  prosecutors  in  Germany  recently 
seized  it,  according  to  Emma  Best,  a  journalist  and  co-founder  of  the  group.  DDOS  says  it  obtained  the  files  from  the  'hacktivist' 
collective  Anonymous,  and  then  made  the  files  searchable  on  a  dedicated  website  on  July  19.  However,  the  site  now  appears  to 
be  down."  Best  said  "German  authorities  seized  the  'primary  public  download  server'  hosting  the  data  dump  without  supplying 
an  explanation.  The  hosting  provider  has  only  said  the  takedown  came  from  the  'department  of  public  prosecution  Zwickau,' 
which  didn't  immediately  respond  to  a  request  for  comment." 
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Greetings  Thomas  Conley  Wednesday,  July  8,  2020 


POLICING  &  POLICY 


5ome  US  States  Consider  Police  Licensing 

Bloomberg  Law  (7/7,  Ebert,  Subscription  Publication)  reports, 
'Government  officials  in  at  least  a  half-dozen  states  want  to  make  it 
aasier  to  end  the  policing  careers  of  abusive  officers  by  making  it  hard 
■  For  them  to  start  fresh  in  new  jurisdictions.  'Now  is  the  time,  I  believe,  to 
Degin  treating  peace  officer  certificates  more  like  licenses,'  said  Ohio 
3ov.  Mike  DeWine.  'The  only  way  the  state  can  revoke  a  peace  officer 
certificate  today  is  if  that  officer  is  convicted  of  a  felony,'  he  said  in 
unveiling  a  proposal  to  beef  up  statewide  oversight  of  law  enforcement. 
There  is  no  mechanism  in  Ohio  to  revoke  a  certificate  for  conduct  that 
■night  be  bad,  might  be  horrible,  but  is  not  necessarily  criminal.'" 
3loomberg  Law  adds,  "Occupational  licensing  proposals  for  law 
enforcement  have  been  pitched  in  recent  weeks  in  California,  Illinois, 
Massachusetts,  New  Jersey,  Ohio,  and  Michigan.  Three  of  those  states  -  California,  Massachusetts,  and  New  Jersey  -  along  with 
Rhode  Island  lack  any  statewide  procedure  for  decertifying  officers." 

San  Diego,  California  To  Put  Police  Reform  Measure  On  November  Ballot 

The  San  Diego  Union-Tribune  (7/7,  Garrick)  reports,  "Critics  of  local  law  enforcement  got  a  key  win  Tuesday  when  the  San 
Diego  City  Council  unanimously  agreed  to  place  a  long-awaited  police  reform  measure  on  the  November  ballot."  According  to 
the  Union-Tribune,  "City  voters  will  get  a  chance  this  November  to  create  a  new  police  oversight  board  that  would  have  the 
power  to  launch  independent  misconduct  investigations,  subpoena  witnesses  and  hold  officers  more  accountable  for  their 


actions.  Community  leaders  and  council  members  said  Tuesday's  vote  was  an  important  milestone  that  would  allow  voters  to 
boost  transparency  and  accountability  for  local  police.  But  they  also  stressed  that  much  more  needs  to  be  done  on  police 
reform."  The  Union-Tribune  adds,  "Other  recent  reform  efforts  in  San  Diego  include  a  ban  on  police  officers  using  carotid 
restraints,  new  Police  Department  de-escalation  procedures  and  creation  of  an  Office  on  Race  and  Equity." 

US  House  Democrats  Include  $597  Million  For  Police  Reform  In  Spending  Bill 

The  Hill  (7/7,  Elis)  reports,  "House  Democrats  included  a  slew  of  police  reforms,  as  well  as  $596.7  million  in  funding  for 
reform  programs,  in  a  proposed  spending  bill  for  the  2021  fiscal  year,  which  begins  in  October."  The  Hill  adds,  "The  2021 
Commerce,  Justice,  Science  appropriations  bill  includes  $400  million  for  initiatives  that  would  boost  independent  investigations 
of  law  enforcement,  pattern  and  practice  investigations  that  look  for  systemic  problems  in  policing,  community-based 
organizations  seeking  to  improve  law  enforcement  and  other  initiatives.  It  would  also  provide  $50  million  to  train  local  law 
enforcement  on  certain  best  practices,  $77.5  million  to  grant  programs  to  boost  police-community  relations,  $25  million  for 
federal  investigations  into  misconduct  and  $4  million  for  civilian  review  boards." 

US  Lawmakers  Unveil  Bill  To  Defund  Police,  Provide  Reparations 

The  New  York  Post  (7/7,  Nelson)  reports  that  US  Reps.  Ayanna  Pressley  (D-MA)  and  Rashida  Tlaib  (D-MI)  on  Tuesday 
"announced  federal  legislation  to  defund  police  and  set  up  reparations  for  people  who  either  are  black  or  were  harmed  by 
cops."  The  two  lawmakers  announced  the  measure  "on  a  Zoom  call,"  but  it  "has  not  yet  been  introduced."  Said  Tlaib,  "We  can 
start  to  envision  through  this  bill  a  new  version  for  public  safety  -  a  new  vision  for  public  safety,  one  that  protects  and  affirms 
Black  lives." 

The  AP  (7/7,  Stafford)  reports,  "Dubbed  the  BREATHE  Act,  the  legislation  is  the  culmination  of  a  project  led  by  the 
policy  table  of  the  Movement  for  Black  Lives,  a  coalition  of  more  than  150  organizations." 

Minnesota  Lawmakers  Remain  Hopeful  About  Police  Reform  Efforts 

The  Minneapolis  StarTribune  (7/8,  Berkel,  Bierschbach)  reports,  "Minnesota  state  lawmakers  will  get  another  chance  at 
passing  police  accountability  measures  into  law  next  week,  with  Gov.  Tim  Walz  planning  to  call  a  special  legislative  session  for 
the  second  time  this  summer."  The  StarTribune  adds,  "Walz  said  Tuesday  he  is  optimistic  that  lawmakers  can  strike  a  deal  on 
both  a  public  works  spending  package  and  on  police  reforms  in  the  wake  of  the  May  death  of  George  Floyd  at  the  hands  of 
Minneapolis  police  officers."  House  Democrats  "continue  to  push  for  a  sweeping  package  of  changes  to  boost  community-led 
alternatives  to  policing,  ban  warrior-style  training  for  officers  and  raise  the  threshold  for  using  deadly  force  from  'apparent'  to 
'imminent'  threats  to  officers  and  others." 


For  U.S.  Members: 

The  2019-2020  Public  Safety  Officer  Medal  of  Valor  is  the  United  States'  highest  public  safety  honor  that  can  be 
awarded  to  law  enforcement  officers,  emergency  medical  personnel,  and  firefighters.  This  award  honors  federal, 
state,  local,  and  tribal  public  safety  officers  who  have  demonstrated  exceptional  bravery,  risking  serious  injury  or 
death,  in  the  line  of  duty.  The  Bureau  of  Justice  Assistance  is  seeking  nominations  for  the  Medal  of  Valor  now 
through  Friday,  July  31,  2020. 

Public  Safety  Officers  can  be  nominated  for  any  qualifying  event  between  June  1,  2019,  and  May  31,  2020.  Public 
Safety  Officers  must  be  nominated  by  the  heads  of  their  agencies  by  July  31,  2020,  at  11:59  p.m.  ET  to  be 
considered  for  this  award.  Agency  heads  may  submit  multiple  nominations  to  honor  several  officers  or  to  honor 
one  officer  for  multiple  separate  events.  Nomination  guidelines  and  stories  of  past  recipients  can  be  found  on 
the  Medal  of  Valor  website. 
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Black  Americans  Report  Hate  Crimes,  Violence  In  Wake  Of  Floyd  Protests 

USA  Today  (7/7,  Philimon)  reports  that  a  "range  of  disturbing  incidents  have  happened  since  George  Floyd's  death  and 
subsequent  protests  against  racism  and  police  brutality."  In  Illinois,  for  example,  "a  man  was  charged  with  a  hate  crime  for 
allegedly  riding  his  motorcycle  into  a  protest  and  hitting  two  people,"  and  "authorities  say  a  KKK  leader  tried  to  run  his  car 
through  a  group  of  peaceful  protesters  in  Virginia." 

The  Washington  Examiner  (7/7,  Smith),  meanwhile,  reports  that  "two  white  residents  of  Martinez,  California,  who 
painted  over  a  Black  Lives  Matter  mural,  have  been  charged  with  a  hate  crime." 

The  Wall  Street  Journal  (7/7,  Kusisto,  Frosch,  Subscription  Publication)  reports  Floyd's  death  has  also  prompted  the 
reexamination  of  older  cases  by  local  prosecutors. 

New  York  City  Police  Arrest  195  In  Fireworks  Crackdown 

WNBC-TV  New  York  (7/7)  reports,  "Nearly  200  illegal  fireworks  have  been  made  in  New  York  City  in  the  two  weeks  since 
Mayor  Bill  de  Blasio  unveiled  a  multi-agency  task  force  to  crack  down  on  the  problem  amid  an  unprecedented  level  of 
complaints,  officials  said  Tuesday."  WNBC-TV  adds,  "The  mayor  revealed  the  task  force,  comprised  of  10  officers  with  the  NYPD 
Intelligence  Bureau,  12  FDNY  Fire  Marshals  and  20  Sheriff's  Bureau  of  Criminal  Investigation  members,  on  June  23.  Its  primary 
goal:  to  disrupt  illegal  fireworks  supply  chains  via  sting  operations  within  and  outside  New  York  City  -  and  officials  say  the  group 
busted  a  total  of  195  people  since  it  was  established.  It's  not  clear  what  prompted  the  extraordinary  surge  in  illegal  fireworks 
usage,  which  prompted  sleep-deprived  New  Yorkers  to  protest  in  front  of  Gracie  Mansion  one  night  last  month  amid  continued 
booming." 

Protesters  Charged  With  Leaking  Police  Document  In  Iowa 

The  AP  (7/7,  Foley)  reports,  "Prosecutors  in  Iowa  have  filed  a  rarely  used  leak  charge  against  Black  Lives  Matter  protesters 
accused  of  stealing  a  confidential  police  document  and  displaying  it  during  a  television  news  broadcast."  The  AP  adds,  "Two 
protesters  are  charged  with  unauthorized  dissemination  of  intelligence  data,  a  felony  that  carries  up  to  five  years  in  prison.  The 
Iowa  Judicial  Branch  says  it's  only  the  second  time  that  the  charge  has  been  filed  since  2010.  It's  intended  to  punish  officers  and 
others  who  share  information  that  could  undermine  criminal  investigations  or  violate  privacy  protections."  According  to  the  AP, 
"The  document  in  question  was  a  Des  Moines  Police  Department  bulletin  that  officers  and  state  troopers  had  with  them  while 
patrolling  a  July  1  protest  at  the  Iowa  Capitol.  The  bulletin  included  photos  of  suspects  who  were  wanted  in  the  destruction  of  a 
Des  Moines  police  car  during  a  June  20  protest." 

Dutch  Police  Arrest  Six,  Uncover  Makeshift  Torture  Chamber 

The  AP  (7/7,  Corder)  reports,  "Dutch  police  arrested  six  men  after  discovering  sea  containers  that  had  been  converted 
into  a  makeshift  prison  and  sound-proofed  'torture  chamber'  complete  with  a  dentist's  chair,  tools  including  pliers  and  scalpels 
and  handcuffs,  a  high  ranking  officer  announced  Tuesday.  Authorities  said  police  conducted  the  raid  before  the  torture 
chamber  could  be  used  and  alerted  potential  victims,  who  went  into  hiding."  The  AP  adds,  "The  grisly  discovery  was  made  last 
month  by  officers  investigating  leads  generated  by  data  from  encrypted  phones  used  by  criminals.  The  communications 
network  was  cracked  recently  by  French  police.  Detectives  in  Britain  and  the  Netherlands  have  already  arrested  hundreds  of 
suspects  based  on  the  encrypted  messages."  According  to  the  AP,  "Tuesday's  announcement  gave  a  chilling  insight  into  the 
increasingly  violent  Dutch  criminal  underworld,  which  is  involved  in  the  large  scale  production  and  trafficking  of  drugs." 

TECHNOLOGY 

German  Authorities  Seize  Server  Hosting  "BlueLeaks"  Data  Dump 

PCMag  (7/7,  Kan)  reports,  "German  authorities  have  confiscated  a  server  hosting  the  "BlueLeaks"  data  dump,  a  269GB 
trove  of  internal  police  documents  that  leaked  last  month."  According  to  PCMag,  "The  Wikileaks-style  group  Distributed  Denial 


of  Secrets  (DDOS)  had  been  using  the  server  to  enable  the  public  to  download  the  files,  but  prosecutors  in  Germany  recently 
seized  it,  according  to  Emma  Best,  a  journalist  and  co-founder  of  the  group.  DDOS  says  it  obtained  the  files  from  the  'hacktivist' 
collective  Anonymous,  and  then  made  the  files  searchable  on  a  dedicated  website  on  July  19.  However,  the  site  now  appears  to 
be  down."  Best  said  "German  authorities  seized  the  'primary  public  download  server'  hosting  the  data  dump  without  supplying 
an  explanation.  The  hosting  provider  has  only  said  the  takedown  came  from  the  'department  of  public  prosecution  Zwickau,' 
which  didn't  immediately  respond  to  a  request  for  comment." 
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POLICING  &  POLICY 


5ome  US  States  Consider  Police  Licensing 

Bloomberg  Law  (7/7,  Ebert,  Subscription  Publication)  reports, 
'Government  officials  in  at  least  a  half-dozen  states  want  to  make  it 
aasier  to  end  the  policing  careers  of  abusive  officers  by  making  it  hard 
■  For  them  to  start  fresh  in  new  jurisdictions.  'Now  is  the  time,  I  believe,  to 
Degin  treating  peace  officer  certificates  more  like  licenses,'  said  Ohio 
3ov.  Mike  DeWine.  'The  only  way  the  state  can  revoke  a  peace  officer 
certificate  today  is  if  that  officer  is  convicted  of  a  felony,'  he  said  in 
unveiling  a  proposal  to  beef  up  statewide  oversight  of  law  enforcement. 
There  is  no  mechanism  in  Ohio  to  revoke  a  certificate  for  conduct  that 
■night  be  bad,  might  be  horrible,  but  is  not  necessarily  criminal.'" 
3loomberg  Law  adds,  "Occupational  licensing  proposals  for  law 
enforcement  have  been  pitched  in  recent  weeks  in  California,  Illinois, 
Massachusetts,  New  Jersey,  Ohio,  and  Michigan.  Three  of  those  states  -  California,  Massachusetts,  and  New  Jersey  -  along  with 
Rhode  Island  lack  any  statewide  procedure  for  decertifying  officers." 

San  Diego,  California  To  Put  Police  Reform  Measure  On  November  Ballot 

The  San  Diego  Union-Tribune  (7/7,  Garrick)  reports,  "Critics  of  local  law  enforcement  got  a  key  win  Tuesday  when  the  San 
Diego  City  Council  unanimously  agreed  to  place  a  long-awaited  police  reform  measure  on  the  November  ballot."  According  to 
the  Union-Tribune,  "City  voters  will  get  a  chance  this  November  to  create  a  new  police  oversight  board  that  would  have  the 
power  to  launch  independent  misconduct  investigations,  subpoena  witnesses  and  hold  officers  more  accountable  for  their 


actions.  Community  leaders  and  council  members  said  Tuesday's  vote  was  an  important  milestone  that  would  allow  voters  to 
boost  transparency  and  accountability  for  local  police.  But  they  also  stressed  that  much  more  needs  to  be  done  on  police 
reform."  The  Union-Tribune  adds,  "Other  recent  reform  efforts  in  San  Diego  include  a  ban  on  police  officers  using  carotid 
restraints,  new  Police  Department  de-escalation  procedures  and  creation  of  an  Office  on  Race  and  Equity." 

US  House  Democrats  Include  $597  Million  For  Police  Reform  In  Spending  Bill 

The  Hill  (7/7,  Elis)  reports,  "House  Democrats  included  a  slew  of  police  reforms,  as  well  as  $596.7  million  in  funding  for 
reform  programs,  in  a  proposed  spending  bill  for  the  2021  fiscal  year,  which  begins  in  October."  The  Hill  adds,  "The  2021 
Commerce,  Justice,  Science  appropriations  bill  includes  $400  million  for  initiatives  that  would  boost  independent  investigations 
of  law  enforcement,  pattern  and  practice  investigations  that  look  for  systemic  problems  in  policing,  community-based 
organizations  seeking  to  improve  law  enforcement  and  other  initiatives.  It  would  also  provide  $50  million  to  train  local  law 
enforcement  on  certain  best  practices,  $77.5  million  to  grant  programs  to  boost  police-community  relations,  $25  million  for 
federal  investigations  into  misconduct  and  $4  million  for  civilian  review  boards." 

US  Lawmakers  Unveil  Bill  To  Defund  Police,  Provide  Reparations 

The  New  York  Post  (7/7,  Nelson)  reports  that  US  Reps.  Ayanna  Pressley  (D-MA)  and  Rashida  Tlaib  (D-MI)  on  Tuesday 
"announced  federal  legislation  to  defund  police  and  set  up  reparations  for  people  who  either  are  black  or  were  harmed  by 
cops."  The  two  lawmakers  announced  the  measure  "on  a  Zoom  call,"  but  it  "has  not  yet  been  introduced."  Said  Tlaib,  "We  can 
start  to  envision  through  this  bill  a  new  version  for  public  safety  -  a  new  vision  for  public  safety,  one  that  protects  and  affirms 
Black  lives." 

The  AP  (7/7,  Stafford)  reports,  "Dubbed  the  BREATHE  Act,  the  legislation  is  the  culmination  of  a  project  led  by  the 
policy  table  of  the  Movement  for  Black  Lives,  a  coalition  of  more  than  150  organizations." 

Minnesota  Lawmakers  Remain  Hopeful  About  Police  Reform  Efforts 

The  Minneapolis  StarTribune  (7/8,  Berkel,  Bierschbach)  reports,  "Minnesota  state  lawmakers  will  get  another  chance  at 
passing  police  accountability  measures  into  law  next  week,  with  Gov.  Tim  Walz  planning  to  call  a  special  legislative  session  for 
the  second  time  this  summer."  The  StarTribune  adds,  "Walz  said  Tuesday  he  is  optimistic  that  lawmakers  can  strike  a  deal  on 
both  a  public  works  spending  package  and  on  police  reforms  in  the  wake  of  the  May  death  of  George  Floyd  at  the  hands  of 
Minneapolis  police  officers."  House  Democrats  "continue  to  push  for  a  sweeping  package  of  changes  to  boost  community-led 
alternatives  to  policing,  ban  warrior-style  training  for  officers  and  raise  the  threshold  for  using  deadly  force  from  'apparent'  to 
'imminent'  threats  to  officers  and  others." 
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The  2019-2020  Public  Safety  Officer  Medal  of  Valor  is  the  United  States'  highest  public  safety  honor  that  can  be 
awarded  to  law  enforcement  officers,  emergency  medical  personnel,  and  firefighters.  This  award  honors  federal, 
state,  local,  and  tribal  public  safety  officers  who  have  demonstrated  exceptional  bravery,  risking  serious  injury  or 
death,  in  the  line  of  duty.  The  Bureau  of  Justice  Assistance  is  seeking  nominations  for  the  Medal  of  Valor  now 
through  Friday,  July  31,  2020. 

Public  Safety  Officers  can  be  nominated  for  any  qualifying  event  between  June  1,  2019,  and  May  31,  2020.  Public 
Safety  Officers  must  be  nominated  by  the  heads  of  their  agencies  by  July  31,  2020,  at  11:59  p.m.  ET  to  be 
considered  for  this  award.  Agency  heads  may  submit  multiple  nominations  to  honor  several  officers  or  to  honor 
one  officer  for  multiple  separate  events.  Nomination  guidelines  and  stories  of  past  recipients  can  be  found  on 
the  Medal  of  Valor  website. 
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CRIME  &  DRUGS 


Black  Americans  Report  Hate  Crimes,  Violence  In  Wake  Of  Floyd  Protests 

USA  Today  (7/7,  Philimon)  reports  that  a  "range  of  disturbing  incidents  have  happened  since  George  Floyd's  death  and 
subsequent  protests  against  racism  and  police  brutality."  In  Illinois,  for  example,  "a  man  was  charged  with  a  hate  crime  for 
allegedly  riding  his  motorcycle  into  a  protest  and  hitting  two  people,"  and  "authorities  say  a  KKK  leader  tried  to  run  his  car 
through  a  group  of  peaceful  protesters  in  Virginia." 

The  Washington  Examiner  (7/7,  Smith),  meanwhile,  reports  that  "two  white  residents  of  Martinez,  California,  who 
painted  over  a  Black  Lives  Matter  mural,  have  been  charged  with  a  hate  crime." 

The  Wall  Street  Journal  (7/7,  Kusisto,  Frosch,  Subscription  Publication)  reports  Floyd's  death  has  also  prompted  the 
reexamination  of  older  cases  by  local  prosecutors. 

New  York  City  Police  Arrest  195  In  Fireworks  Crackdown 

WNBC-TV  New  York  (7/7)  reports,  "Nearly  200  illegal  fireworks  have  been  made  in  New  York  City  in  the  two  weeks  since 
Mayor  Bill  de  Blasio  unveiled  a  multi-agency  task  force  to  crack  down  on  the  problem  amid  an  unprecedented  level  of 
complaints,  officials  said  Tuesday."  WNBC-TV  adds,  "The  mayor  revealed  the  task  force,  comprised  of  10  officers  with  the  NYPD 
Intelligence  Bureau,  12  FDNY  Fire  Marshals  and  20  Sheriff's  Bureau  of  Criminal  Investigation  members,  on  June  23.  Its  primary 
goal:  to  disrupt  illegal  fireworks  supply  chains  via  sting  operations  within  and  outside  New  York  City  -  and  officials  say  the  group 
busted  a  total  of  195  people  since  it  was  established.  It's  not  clear  what  prompted  the  extraordinary  surge  in  illegal  fireworks 
usage,  which  prompted  sleep-deprived  New  Yorkers  to  protest  in  front  of  Gracie  Mansion  one  night  last  month  amid  continued 
booming." 

Protesters  Charged  With  Leaking  Police  Document  In  Iowa 

The  AP  (7/7,  Foley)  reports,  "Prosecutors  in  Iowa  have  filed  a  rarely  used  leak  charge  against  Black  Lives  Matter  protesters 
accused  of  stealing  a  confidential  police  document  and  displaying  it  during  a  television  news  broadcast."  The  AP  adds,  "Two 
protesters  are  charged  with  unauthorized  dissemination  of  intelligence  data,  a  felony  that  carries  up  to  five  years  in  prison.  The 
Iowa  Judicial  Branch  says  it's  only  the  second  time  that  the  charge  has  been  filed  since  2010.  It's  intended  to  punish  officers  and 
others  who  share  information  that  could  undermine  criminal  investigations  or  violate  privacy  protections."  According  to  the  AP, 
"The  document  in  question  was  a  Des  Moines  Police  Department  bulletin  that  officers  and  state  troopers  had  with  them  while 
patrolling  a  July  1  protest  at  the  Iowa  Capitol.  The  bulletin  included  photos  of  suspects  who  were  wanted  in  the  destruction  of  a 
Des  Moines  police  car  during  a  June  20  protest." 

Dutch  Police  Arrest  Six,  Uncover  Makeshift  Torture  Chamber 

The  AP  (7/7,  Corder)  reports,  "Dutch  police  arrested  six  men  after  discovering  sea  containers  that  had  been  converted 
into  a  makeshift  prison  and  sound-proofed  'torture  chamber'  complete  with  a  dentist's  chair,  tools  including  pliers  and  scalpels 
and  handcuffs,  a  high  ranking  officer  announced  Tuesday.  Authorities  said  police  conducted  the  raid  before  the  torture 
chamber  could  be  used  and  alerted  potential  victims,  who  went  into  hiding."  The  AP  adds,  "The  grisly  discovery  was  made  last 
month  by  officers  investigating  leads  generated  by  data  from  encrypted  phones  used  by  criminals.  The  communications 
network  was  cracked  recently  by  French  police.  Detectives  in  Britain  and  the  Netherlands  have  already  arrested  hundreds  of 
suspects  based  on  the  encrypted  messages."  According  to  the  AP,  "Tuesday's  announcement  gave  a  chilling  insight  into  the 
increasingly  violent  Dutch  criminal  underworld,  which  is  involved  in  the  large  scale  production  and  trafficking  of  drugs." 

TECHNOLOGY 

German  Authorities  Seize  Server  Hosting  "BlueLeaks"  Data  Dump 

PCMag  (7/7,  Kan)  reports,  "German  authorities  have  confiscated  a  server  hosting  the  "BlueLeaks"  data  dump,  a  269GB 
trove  of  internal  police  documents  that  leaked  last  month."  According  to  PCMag,  "The  Wikileaks-style  group  Distributed  Denial 


of  Secrets  (DDOS)  had  been  using  the  server  to  enable  the  public  to  download  the  files,  but  prosecutors  in  Germany  recently 
seized  it,  according  to  Emma  Best,  a  journalist  and  co-founder  of  the  group.  DDOS  says  it  obtained  the  files  from  the  'hacktivist' 
collective  Anonymous,  and  then  made  the  files  searchable  on  a  dedicated  website  on  July  19.  However,  the  site  now  appears  to 
be  down."  Best  said  "German  authorities  seized  the  'primary  public  download  server'  hosting  the  data  dump  without  supplying 
an  explanation.  The  hosting  provider  has  only  said  the  takedown  came  from  the  'department  of  public  prosecution  Zwickau,' 
which  didn't  immediately  respond  to  a  request  for  comment." 
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https://www.vice.com/en_us/article/qj43xq/cops-seize-blueleaks-ddosecrets-server 

By  Lorenzo  Franceschi-Bicchierai 

Vice.com 

July  7,  2020 

Authorities  in  Germany  have  seized  a  server  used  by  the  organization  that 
published  a  trove  of  US  police  internal  documents  commonly  known  as  BlueLeaks, 
according  to  the  organization’s  founder. 

On  Tuesday,  Emma  Best,  the  founder  of  Distributed  Denial  of  Secrets  or 
DDoSecrets,  a  WikiLeaks-like  website  that  has  published  the  police  data,  said 
that  prosecutors  in  the  German  town  of  Zwickau  seized  the  organization’s 
“primary  public  download  server.” 

“We  are  working  to  obtain  additional  information,  but  presume  it  is  [regarding] 

#BlueLeaks,”  Best  added  on  Twitter.  “The  server  was  used  ONLY  to  distribute  data 
to  the  public.  It  had  no  contact  with  sources  and  was  involved  in  nothing  more 
than  enlightening  the  public  through  journalistic  publishing.” 

Best  shared  a  screenshot  of  the  email  they  received  from  DDoSecrets’  hosting 
provider  informing  of  the  server  seizure. 
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Delivery  Hero  Confirms  Foodora  Data  Breach 

Personal  Details  on  727,000  Accounts  in  14  Countries  Leaked 
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‘BlueLeaks’  Exposes  Files  from  Hundreds  of 
Police  Departments 

Hundreds  of  thousands  of  potentially  sensitive  files  from  police 
departments  across  the  United  States  were  leaked  online  last  week. 
The  collection,  dubbed  “  BlueLeaks  ”  and  made  searchable  online, 
stems  from  a  security  breach  at  a  Texas  web  design  and  hosting 
company  that  maintains  a  number  of  state  law  enforcement  data- 
sharing  portals. 
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schools  defend  themselves  Now  COVID-19  has  dramatically  and 
permanently  expanded  that  parental  responsibility,  as  well  as 
extended  it  to  ill-prepared  school  officials  in  K-12  campuses  all  across 
the  nation. 
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SPONSORED  BY  LOOKINGGLASS  CYBER  SOLUTIONS: 

Lure  &  Deceive:  Using  Deception  Technology  to  Defeat  your 
Adversary 

Staying  one  step  ahead  of  your  adversaries  is  more  challenging  than  ever.  Fortunately, 
deception  technology  can  give  new  visibility  and  intelligence  in  combating  threat  actors  who 
seek  to  infiltrate  your  network. 

View  our  on-demand  webinar  to  learn  how  to  optimize  your  deception  technology  investments 
to  enhance  your  day-to-day  security  threat  detection  and  mitigation  activities. 
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July  8,  2020. 


SUMMARY 


By  the  CyberWire  staff 

It  appears  increasingly  likely  that  the  explosion  at  Iran's  Natanz  nuclear  facility  was  sabotage, 
and  not  a  cyberattack  (EurAsian  Times  has  a  summary  of  the  emerging  consensus).  The 
connections,  if  any,  between  the  Natanz  incident  and  damage  recently  worked  elsewhere  in 
Iran  remain  unclear,  Haaretz  notes,  but  it  does  seem  that  Iran's  nuclear  program  figures  on 
some  adversary's  target  list. 

The  US  Cybersecurity  and  Infrastructure  Security  Agency  (CISA)  yesterday  released  its 
strategy  document,  Securing  Industrial  Control  Systems:  A  Unified  Initiative. 

At  a  speech  before  the  Hudson  Institute  yesterday,  US  FBI  Director  Wray  denounced  Chinese 
intelligence  operations  as,  according  to  Axios,  serving  Beijing's  ambitions  to  become  the 
world's  dominant  power.  CNBC's  coverage  of  the  speech  concentrated  on  Director  Wray's 
account  of  Chinese  industrial  espionage. 

Vice  reports  that  police  in  Zwickau,  Saxony,  seized  the  server  used  by  DDoSecrets,  aspiring 
successor  to  WikiLeaks.  DDoSecrets  doesn't  know  why  the  server  was  taken,  but  assumes 
the  seizure  was  due  to  the  group's  BlueLeaks  program  of  doxing  US  police  departments. 

Bloomberg  Law  reports  that  Mexico's  central  bank  sustained  but  successfully  parried  a 
cyberattack  yesterday.  Banco  de  Mexico  said  that  the  denial-of-service  attempt  lasted  about 
half  an  hour  and  caused  brief,  intermittent  outages  before  it  was  finally  stopped,  and  service 
returned  to  normal. 

EDP  Renewables  North  America,  a  renewable  energy  subsidiary  of  Energias  de  Portugal,  has 
disclosed  a  databreach.  The  company  characterizes  it  as  unauthorized  intrusion  into  its 
networks,  but  says  it  believes  no  customer  data  were  compromised.  SecurityWeek  calls  the 
incident  a  Ragnar  Locker  ransomware  infection. 
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Notes. 

Today's  issue  includes  events  affecting  Brazil,  China,  France,  Germany,  India,  Mexico, 
Russia,  the  United  Arab  Emirates,  and  the  United  States. 

Word  Notes  Wednesday. 

copy-paste  compromise  (Noun):  Successful  breaches  accomplished  using  only  open-source 
tools.  The  adversary  uses  no  original  code  to  traverse  the  intrusion  kill  chain. 


Aerospace  news  worthy  of  attention. 


If  you're  interested  in  space  and  communications  (technology,  policy,  business,  and 
operations),  take  a  look  at  the  latest  issue  of  Cosmic  AES  Signals  &  Space.  Produced  in 
partnership  with  the  CyberWire,  Signals  &  Space  offers  a  monthly  overview  of  news  in  this 
sector. 
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Available  Now:  Mandiant  Security  Effectiveness  Report  2020 

Government  agencies  are  the  third  most  targeted  industry  by  threat  actors.  In  order  to  be 
prepared  for  cyber  incidents,  they  need  tools  to  measure  their  security  effectiveness  so  they 
can  understand  &  manage  their  cyber  risks.  The  Security  Effectiveness  Report  2020  gives 
you  a  detailed  look  at  these  threats  and  how  you  combat  this  reality. 


ON  THE  PODCAST 


In  today's  CyberWire  Daily  Podcast,  out  later  this  afternoon,  we  speak  with  our  partners  at  the 
Johns  Hopkins  University's  Information  Security  Institute,  as  Joe  Carriqan  talks  about 
personal  privacy  measures  for  iOS  and  Android.  Our  guest,  Steve  Moore  from  Exabeam,  has 
spent  a  good  year  interviewing  CISOs,  and  he  shares  what  he's  learned  from  his  interlocutors. 

And  Caveat  is  up.  In  this  week's  episode,  "Huawei  statements  are  not  as  strong  as  before," 
Dave's  got  the  story  of  a  school  district  in  hot  water  over  facial  recognition  issues,  Ben  has  the 
story  of  protesters  being  tracked  via  their  mobile  devices,  and  later  in  the  show  our 
conversation  with  Shannon  Vavra  with  CyberScoop  on  her  recent  article,  "Huawei  execs 
admit  they  don't  know  whether  their  tech  is  used  for  surveillance." 


SPONSORED  EVENTS 


OSINT  Insiders:  The  Rise  and  Evolution  of  Open  Source  Intelligence  (Online,  July  10, 
2020)  Join  OSINT  Insiders  live  on  Friday,  July  10!  Major  General  (Retired)  Mark  R.  Quantock 
of  Babel  Street  will  share  his  perspective  on  the  rise  of  Open  Source  Intelligence  (OSINT)  and 
how  it  has  evolved  over  the  years. 

Cyber  Security  Summit  Virtual  Power  Hour  -  Get  the  Facts  on  July  14  and  16  (Online, 

July  14-  16,  2020)  Senior  Level  Executives  are  invited  to  the  upcoming  Cyber  Summit  Virtual 
Power  Hours.  Learn  from  Industry  Experts  from  The  FBI,  U.S.  Secret  Service,  U.S.  DHS, 
Google,  IBM  Security,  KnowBe4  &  Duo  Security  as  they  discuss  the  latest  security  challenges 
&  develop  cyber  security  battle  plans  in  today’s  unprecedented  times.  You  will  receive  1  CPE 
/  CEU  credit  by  attending.  Free  to  register  with  code:  CyberWire20  at  CyberSummitUSA.com. 


loT  Integrator  Summit:  Securing  Edge  Computing  (Online,  July  14  -  16,  2020)  A  virtual 
summit  to  help  loT  Integrators  learn  more  about  advances  and  updates  in  loT  security  and 


discover  new  methods  for  architecting  loT  solutions  for  your  organization  or  your  clients. 


RSA  Conference  APJ  July  15-17,  2020  -  A  Virtual  Learning  Experience  (Online,  July  15  - 
17,  2020)  The  world’s  leading  cybersecurity  event  is  going  virtual  15-17  July.  Join  your  peers 
and  industry  experts  for  three  days  of  insights.  Watch  over  50  sessions  live  during  Singapore 
business  hours — or  stream  them  later.  Register  today  for  free. 
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Cyber  Attacks,  Threats,  and  Vulnerabilities 

Attack  On  Iran’s  Natanz  Nuclear  Facility  Not  A  Cyber  Attack.  But  A  Bomb  Blast  - 

Reports  (EurAsian  Times)  The  recent  explosion  at  Natanz  nuclear  facility  in  Iran  has  set  back 
its  nuclear  program  by  more  than... 

Experts:  Natanz  explosion  set  back  Iran’s  nuclear  program  by  more  than  a  year 

(Haaretz)  It's  unclear  if  the  explosion  and  other  incidents  that  occurred  in  Iran  over  the  past 
week  were  connected,... 

Mexico’s  Central  Bank  Thwarts  Cyber  Attack  on  Its  Website  (Bloomberg  Law)  Mexico’s 
central  bank  said  it  thwarted  a  cyberattack  on  its  website  Tuesday,  although  its  web  page 
had... 

Find  MORE  on  our  website. 


Security  Patches,  Mitigations,  and  Software  Updates 

New  round  of  bugs  found  in  Citrix  software,  but  this  time  a  patch  is  ready  (CyberScoop) 
On  Tuesday,  Citrix  revealed  1 1  new  vulnerabilities  in  its  cloud-based  and  remote  access 
products,  ADC... 

Citrix  tells  everyone  not  to  worry  too  much  over  its  latest  security  patches.  NSA's 

former  top  hacker  disagrees  (Register)  Eleven  flaws  cleaned  up  including  one  that  may  be 
exploited  to  sling  malware  downloads 

Mozilla  turns  off  “Firefox  Send”  following  malware  abuse  reports  (Naked  Security)  Sadly, 
the  easier  and  safer  you  make  your  file  sharing  service,  the  more  attractive  it  becomes  to 
the... 

Find  MORE  on  our  website. 

Cyber  Trends 

Bitqlass  2020  BYOD  Report:  Increased  Remote  Work  Drives  BYOD,  but  Security  is  Not 

Keeping  Pace  (BusinessWire)  Bitglass,  the  Total  Cloud  Security  company,  has  released  its 
2020  BYOD  Report,  which  analyzes  enterprise... 

M&D  Report  (Sikich  LLP)  M&D  Report  2019  Sikich’s  fifth  Manufacturing  &  Distribution  survey 
was  recently  completed — and  the  results... 

Physical  stress  to  phishing:  Real  challenges  of  virtual  gaming  and  howto  counter  them 


(Firstpost)  The  rapidly-growing  Esports  industry  has  its  own  issues  that  manifest  in  the  form  of 
various  risks  associated... 

Marketplace 

Tech  Startups  Hemorrhaging  Jobs  During  Pandemic  (Channel  Futures)  A  new  BuyShares 
report  shows  tech  startups  have  been  heavily  impacted  by  the  COVID-19  pandemic,  with... 

Thoma  Bravo  acquires  Exostar  (PE  Hub)  Thoma  Bravo  has  acquired  Exostar  LLC,  a 
provider  of  secure  business  collaboration  solutions. 

QOMPLX  announces  plans  for  US  insurance  subsidiary  RubiQon  Risk/RubiQon  Re  (PR 

Newswire)  QOMPLX™,  an  intelligent  decision  platform  provider,  today  announced  the  launch 
of  a  US-based  subsidiary... 

Find  MORE  on  our  website. 

Products,  Services,  and  Solutions 

iProov  Provides  Online  Biometric  Safeguarding  for  Interqenerational  Mentoring 

Platform,  bloomd  (BusinessWire)  iProov,  world-leaders  in  spoof-resistant  biometric 
authentication  technology,  is  continuing  to  provide... 

Bricata  Partners  with  Elastic  to  Deliver  Comprehensive  Network  Securit  (PRWeb) 
Bricata,  Inc.,  a  leading  provider  of  comprehensive  network  protection,  today  announced  a 
technology  partnership... 

New  F5  Solution  Defends  Customers’  Websites  through  Protection  against  Bots  and 

Credential  Stuffing  (BusinessWire)  F5  (NASDAQ:  FFIV)  today  unveiled  Silverline  Shape 
Defense,  a  security  solution  that  protects  websites... 

Find  MORE  on  our  website. 

Technologies,  Techniques,  and  Standards 

Cyber  Command  will  get  a  new  version  of  its  training  platform  this  fall  (C4ISRNET)  The 
Persistent  Cyber  Training  Environment  is  slated  to  deliver  its  second  version  to  the  cyber 
mission... 

Marine  Corps  activates  new  battalion  to  fight  in  cyberspace  (Camp  Lejeune  Globe)  An 
impactful  change  to  Marine  Corps  cyberspace  and  information  technology  modernization 
occurred  June... 

Adopt  These  Video  Conferencing  Security  Best  Practices  to  Strengthen  Your  Digital 

Security  (Security  Intelligence)  Video  conferencing  use  spiked  during  COVID-19  due  to 
remote  work,  but  security  risks  were  likely  overlooked. 

Design  and  Innovation 

Scrutiny  is  key  to  the  success  of  digital  immunity  passports  (Computing)  Is  the 
convenience  of  a  digital  coronavirus  immunity  document  worth  the  privacy  concerns  and 


investment,... 


Hardware  enclaves  -  the  next  frontier  in  enterprise  application  security  (diginomica) 
Hardware  enclaves  -  security's  next  big  thing. 

Research  and  Development 

Ben-Gurion  University  researchers  determine  how  to  accurately  pinpoint  malicious 

drone  operators  (EurekAlert!)  When  tested  in  simulated  drone  paths,  the  model  was  able  to 
predict  the  operator  location  with  78%  accuracy. 

Academia 

NSA  designates  Wright  State  center  for  cyber  defense  education  (Dayton  Daily  News) 
Wright  State  University  has  won  a  federal  designation  as  a  go-to  center  for  cyber  defense 
education. 

Legislation,  Policy,  and  Regulation 

China’s  Second  Wave  of  Coronavirus  Censorship  Is  Here  (Foreign  Policy)  After  a  brief 
period  of  praising  whistleblowers,  Beijing  is  targeting  medical  staff  and  COVID-1 9  victims... 

In  Hong  Kong  National  Security  Law,  Echoes  of  China's  Own  Cyber  Crackdown  (New 

York  Times)  Hong  Kong's  new  National  Security  Law  will  shake  up  digital  surveillance  in  the 
city,  with  strict  new... 

China  aims  to  dominate  everything  from  5G  to  Al  (CNET)  Generation  China  is  a  CNET 
series  looking  at  how  the  country  is  staking  out  positions  in  the  biggest... 

Find  MORE  on  our  website. 

Litigation,  Investigation,  and  Law  Enforcement 

Exclusive:  U.S.  probing  allegations  TikTok  violated  children's  privacy  -  sources 

(Reuters)  The  Federal  Trade  Commission  and  the  U.S.  Justice  Department  are  looking  into 
allegations  that  popular... 

Russia  Arrests  Space  Agency  Official,  Accusing  Him  of  Treason  (New  York  Times)  The 
detention  of  Ivan  Safronov,  a  former  journalist  who  had  been  working  as  an  adviser  at 
Roscosmos,... 

Lawmakers  paralyzed  over  response  to  Russian  bounty  intel  (POLITICO)  Trump  has 
called  initial  reporting  on  the  bounties  a  hoax. 

Find  MORE  on  our  website. 
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Newly  Noted  Events 

The  Future  of  Digital  Engagement  Is  Here  (Online,  July  29,  2020)  Businesses  are  facing  a 
period  of  complex  global  change  and  disruption.  What’s  on  the  horizon?  Akamai... 

Upcoming  Events 

WSIS  Forum  2020  (Online,  June  22  -  September  1 0,  2020)  The  World  Summit  on  the 
Information  Society  (WSIS)  Forum  2020,  celebrates  15  years  of  providing  a  multi¬ 
stakeholder... 

Inaugural  Toronto  Cyber  Security  Summit  (Toronto,  Ontario,  Canada,  July  14,  2020)  C- 
Suite  &  Senior  Level  Executives:  Register  with  Promo  Code  CYBERWIRE95  to  receive  $95 
Admission  (Standard... 

SecureWorld  Boston  2020  Virtual  Conference  (Online,  July  15,  2020)  Join  the 
cybersecurity  community  for  high-quality  training  and  collaboration  through  an  interactive 
online... 

7th  Annual  DC  Metro  Cyber  Security  Summit  (McLean,  Virginia,  USA,  July  23,  2020)  C- 
Suite  &  Senior  Level  Executives:  Register  with  Promo  Code  CYBERWIRE95  to  receive  $95 
Admission  (Standard... 

SecureWorld  New  York  -  Philadelphia  Virtual  Conference  2020  (Online,  July  29,  2020) 
Join  the  cybersecurity  community  for  high-quality  training  and  collaboration  through  an 
interactive  online... 
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4.  Citrix  patches  1 1  critical  bugs  (InfoSec  News) 
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https://www.zdnet.com/article/edp-energy-confirms-cyberattack-ragnar-locker-ransomware-blamed/ 

By  Charlie  Osborne 
Zero  Day 
ZDNet.com 
July  7,  2020 

EDP  Renewables  North  America  (EDPR  NA)  has  disclosed  a  cyberattack  in 
which  ransomware  landed  on  parent  company  Energias  de  Portugal  (EDP)'s 
systems,  potentially  leading  to  information  exposure. 

In  a  letter  sent  to  customers  (.PDF),  the  energy  company  apologized  for 
the  incident  but  insisted  that  there  is  "no  evidence"  that  consumer 
information  was  compromised  or  stolen. 

The  firm  delivers  energy  to  over  1 1  million  customers  and  operates  in  19 
countries. 

EDP  experienced  a  ransomware  attack  on  April  13.  EDPR  NA  learned  of  the 
ransomware  infection  "for  the  first  time"  from  its  parent  company  on  May 
8. 
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https://www.vice.com/en_us/article/qj43xq/cops-seize-blueleaks-ddosecrets-server 

By  Lorenzo  Franceschi-Bicchierai 

Vice.com 

July  7,  2020 


Authorities  in  Germany  have  seized  a  server  used  by  the  organization  that 
published  a  trove  of  US  police  internal  documents  commonly  known  as  BlueLeaks, 
according  to  the  organization?s  founder. 


On  Tuesday,  Emma  Best,  the  founder  of  Distributed  Denial  of  Secrets  or 
DDoSecrets,  a  WikiLeaks-like  website  that  has  published  the  police  data,  said 
that  prosecutors  in  the  German  town  of  Zwickau  seized  the  organization?s 
?primary  public  download  server.? 

?We  are  working  to  obtain  additional  information,  but  presume  it  is  [regarding] 
#BlueLeaks,?  Best  added  on  Twitter.  ?The  server  was  used  ONLY  to  distribute  data 
to  the  public.  It  had  no  contact  with  sources  and  was  involved  in  nothing  more 
than  enlightening  the  public  through  journalistic  publishing.? 

Best  shared  a  screenshot  of  the  email  they  received  from  DDoSecrets?  hosting 
provider  informing  of  the  server  seizure. 

[...] 
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https://medium.eom/@iHeartMalware/today-is-the-day-i-have-dreaded-for-the-last-5-years-51db99ee38fa 

Ronnie  T 
Jul  7,  2020 

September  201 5  is  when  it  all  started.  At  the  time  I  was  working  at  PhishMe 
(now  Cofense),  and  our  CFO  received  a  shady  looking  email,  asking  if  he  was 
busy. 

?l  have  no  idea  what  this  is,  can  you  guys  take  a  look  at  it?  Rohyt  didn?t  send 
this  email.? 

Aaron  and  I  started  looking  at  the  email  to  figure  out  what  was  going  on.  At 
the  time  emails  never  needed  a  response,  because  malicious  emails  were  just 
that:  malicious,  and  always  contained  malware.  This  one  was  a  little  different, 
as  there  was  no  malware  to  be  found.  Where?s  the  macro  or  link?  Where?s  the 
payload?  My  handle  is  literally  ?iHeartMalware?,  but  there?s  no  way  to  infect  a 
user  with  this.  It?s  just  someone  asking  fo-AH  HA! 

The  email  wanted  our  CFO  to  do  a  wire  transfer,  but  we  were  still  lacking 
context.  Why  did  they  want  a  wire  transfer?  Aaron  suggest  responding  back  to 
the  scammers  to  see  how  it  played  out,  and  we  did.  Without  missing  a  beat  the 
scammers  responded,  sent  a  bank  account,  and  asked  for  us  to  transfer  money  to 
an  account  under  their  control.  We  published  the  research,  and  even  referenced 
the  FBI  statistics  of  2015  from  Mr.  Brian  Krebs  himself,  FBI  lost  1.2  billion 


dollars  to  Business  Email  Scams.  OMG,  a  billion  dollars?  That?s  a  lot  of  money 
being  lost,  and  we  should  probably  start  trying  to  figure  this  out. 

Current  me  is  looking  back  at  past  me: 

The  more  we  studied  this  new  thing  called  business  email  compromise,  the  worse 
it  got.  We  started  working  with  other  private  companies  to  try  and  understand 
the  problem,  and  that?s  when  the  BEC  mailing  list  was  born.  Christmas  of  2015. 
Initially  we  were  100  security  professionals  and  10  FBI  agents,  and  our  goal 
was  that:  to  study  and  begin  to  understand  how  this  BEC  mess  worked.  Everything 
was  held  at  the  TLP:Red  level  as  a  way  to  ensure  that  information  could  be 
shared  freely  and  securely,  and  collaboration  worked.  It  worked  really  well. 

1 1 0  people,  we  got  this,  right?  ?Ffight? 

3.1  billion. 

[-] 
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By  William  Knowles  @c4i 
Senior  Editor 
InfoSec  News 
July  8,  2020 

In  a  breath  of  fresh  air  for  this  week,  software  vendor  Citrix  released  patches 
for  1 1  vulnerabilities,  quickly  applying  the  lesson  learned  six  months  ago  and 
not  wanting  a  repeat  with  malicious  hackers  looking  for  ways  to  exploit  the 
vulnerability. 

Citrix  Chief  Information  Security  Officer,  Fermin  J.  Serna  released  a  bulletin 
on  Tuesday,  July  7,  which  covered  a  set  of  vulnerabilities  in  Citrix?s 
products?  Citrix  ADC,  Citrix  Gateway,  and  Citrix  SD-WAN  WANOP  edition.  Standard 
procedure  for  most  software  companies  in  advising  customers  of  vulnerabilities 
is  limited  to  the  publication  of  the  bulletin  and  related  CVEs. 

Serna  took  the  opportunity  to  explain  the  following  points  as  it  relates  to 
CTX276688. 
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By  Jessica  Davis 
Health  IT  Security.com 
July  7,  2020 

July  07,  2020  -  The  extent  of  the  ransomware  attack  that  hit  Arizona-based 
Magellan  Health  in  April  became  clear  this  week,  with  eight  Magellan  Health 
affiliates  and  healthcare  providers  reporting  breaches  stemming  from  the 
incident  to  the  Department  of  Health  and  Human  Services.  The  breach  reporting 
tools  shows  about  365,000  patients  were  affected. 

In  April,  the  Fortune  500  company  was  reportedly  the  victim  of  a  sophisticated 
cyberattack,  in  which  hackers  first  exfiltrated  data  before  deploying  the 
ransomware  payload.  By  leveraging  a  social  engineering  phishing  scheme  that 
impersonated  a  Magellan  client,  the  attackers  were  able  to  gain  access  to  the 
system  five  days  before  the  ransomware  attack. 

The  investigation  determined  hackers  first  installed  malware  able  to  steal 
employee  credentials  and  passwords  to  gain  access  to  the  affected  server. 

Patient  data  was  also  compromised  in  the  event,  including  health-related 
information  such  as  health  insurance  account  data  and  treatment  information. 

The  attack  was  contained  to  a  single  corporate  server,  which  compromised  the 
data  of  current  employees  and  a  trove  of  sensitive  patient  data,  from  Social 
Security  numbers  and  W-2  information,  to  taxpayer  identification  and  employee 
ID  numbers. 

[...] 
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https://www.wired.com/story/russian-hackers-email-scams/ 

By  Lily  Hay  Newman 
Security 
Wired.com 
July  7,  2020 

FOR  YEARS,  COSTLY  email  grifts  have  largely  been  the  provenance  of  West 
African  scammers,  particularly  those  based  in  Nigeria.  A  newly  discovered 
"business  email  compromise"  campaign,  though,  appears  to  come  from  a 
criminal  group  in  a  part  of  the  world  better  known  for  a  different  brand 
of  online  mayhem:  Russia. 

Dubbed  Cosmic  Lynx,  the  group  has  carried  out  more  than  200  BEC  campaigns 
since  July  2019,  according  to  researchers  from  the  email  security  firm 
Agari,  particularly  targeting  senior  executives  at  large  organizations  and 
corporations  in  46  countries.  Cosmic  Lynx  specializes  in  topical,  tailored 
scams  related  to  mergers  and  acquisitions;  the  group  typically  requests 
hundreds  of  thousands  or  even  millions  of  dollars  as  part  of  its  hustles. 

The  researchers,  who  have  worked  extensively  on  tracking  Nigerian  BEC 
scammers,  say  they  don't  have  a  clear  sense  of  how  often  Cosmic  Lynx 
actually  succeeds  at  obtaining  a  payout.  Given  that  the  group  hasn't 
lowered  its  asks  in  a  year,  though,  and  has  been  prolific  about  developing 
new  campaigns?including  some  compelling  Covid-19?related  scams?Agari 
reasons  that  Cosmic  Lynx  must  be  raking  in  a  fair  amount  of  money. 

"Most  Eastern  European  and  Russian  hackers  have  been  so  entrenched  in 
malware  campaigns  and  technically  sophisticated  infrastructure  that,  as 
long  as  there  are  returns,  they  don?t  need  to  adapt,"  says  Crane  Hassold, 
senior  director  of  threat  research  at  Agari  and  a  former  digital  behavior 
analyst  for  the  Federal  Bureau  of  Investigation.  "But  defenses  against 
technically  sophisticated  attacks  have  gotten  significantly  better,  and 
they're  realizing  that  the  return  on  investment  for  these 
social-engineering-based  attacks  is  much  higher." 

West  African  scammers  typically  run  their  BEC  campaigns  off  of  rented  or 
free  cloud  infrastructure  using  free  email  accounts.  They  have 
increasingly  branched  out  into  utilizing  off-the-shelf  hacking  tools  like 
keyloggers  and  even  backdoors  into  targets'  systems,  but  malware  has 
typically  not  played  a  major  role.  Overhead  is  much  lower  when  you  don't 
need  to  develop  and  maintain  your  own  infrastructure  and  software.  This 
may  have  been  a  selling  point  for  Cosmic  Lynx,  which  combines  some  of  the 
technical  chops  of  a  Russian  criminal  hacking  group  with  the  cost  savings 
of  a  classic,  low-tech  BEC  attack. 
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https://siliconangle.com/2020/07/02/customer-data-fitness-company-v-shred-exposed-misconfigured-cloud-storage/ 

By  Duncan  Riley 
SiliconAngle.com 
July  2,  2020 

Data  relating  to  at  least  99,000  customers  of  fitness  company  V  Shred  LLC  has 
been  exposed  online  in  yet  another  case  of  misconfigured  cloud  storage. 

Discovered  by  security  researchers  Noam  Rotem  and  Ran  Locar  at  vpnMentor  and 
reported  today,  the  unsecured  data  was  found  in  an  Amazon  Web  Services  Inc.  S3 
bucket.  The  data,  which  came  in  at  a  sizable  606  gigabytes,  included  about  1.3 
million  files  relating  to  V  Shred  customers. 

The  database  included  full  names,  home  addresses,  email  addresses,  phone 
numbers,  birthdays,  Social  Security  numbers,  spouse  names,  social  media 
accounts,  gender,  health  conditions,  age  range,  citizenship  status,  usernames 
and  passwords.  The  database  also  included  account  profile  photos,  ?revealing? 
before  and  after  photos  and  custom  meal  plans. 

The  exposed  database  was  discovered  on  May  14,  with  V  Shred  contacted  May  18. 

After  no  response  from  the  company,  the  researchers  then  contacted  AWS  May  20. 

AWS  responded  June  1  and  the  database  was  taken  offline  June  18. 

[...] 
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POLICING  &  POLICY 


Some  US  States  Consider  Police  Licensing 

Bloomberg  Law  (7/7,  Ebert,  Subscription  Publication)  reports, 
'Government  officials  in  at  least  a  half-dozen  states  want  to  make  it 
aasier  to  end  the  policing  careers  of  abusive  officers  by  making  it  hard 
For  them  to  start  fresh  in  new  jurisdictions.  'Now  is  the  time,  I  believe,  to 
Degin  treating  peace  officer  certificates  more  like  licenses,'  said  Ohio 
3ov.  Mike  DeWine.  'The  only  way  the  state  can  revoke  a  peace  officer 
certificate  today  is  if  that  officer  is  convicted  of  a  felony,'  he  said  in 
unveiling  a  proposal  to  beef  up  statewide  oversight  of  law  enforcement. 
There  is  no  mechanism  in  Ohio  to  revoke  a  certificate  for  conduct  that 
might  be  bad,  might  be  horrible,  but  is  not  necessarily  criminal.'" 
3loomberg  Law  adds,  "Occupational  licensing  proposals  for  law 
enforcement  have  been  pitched  in  recent  weeks  in  California,  Illinois,  Massachusetts,  New  Jersey,  Ohio,  and  Michigan.  Three  of 
those  states  -  California,  Massachusetts,  and  New  Jersey  -  along  with  Rhode  Island  lack  any  statewide  procedure  for 
decertifying  officers." 

San  Diego,  California  To  Put  Police  Reform  Measure  On  November  Ballot 

The  San  Diego  Union-Tribune  (7/7,  Garrick)  reports,  "Critics  of  local  law  enforcement  got  a  key  win  Tuesday  when  the  San 
Diego  City  Council  unanimously  agreed  to  place  a  long-awaited  police  reform  measure  on  the  November  ballot."  According  to 
the  Union-Tribune,  "City  voters  will  get  a  chance  this  November  to  create  a  new  police  oversight  board  that  would  have  the 
power  to  launch  independent  misconduct  investigations,  subpoena  witnesses  and  hold  officers  more  accountable  for  their 
actions.  Community  leaders  and  council  members  said  Tuesday's  vote  was  an  important  milestone  that  would  allow  voters  to 
boost  transparency  and  accountability  for  local  police.  But  they  also  stressed  that  much  more  needs  to  be  done  on  police 
reform."  The  Union-Tribune  adds,  "Other  recent  reform  efforts  in  San  Diego  include  a  ban  on  police  officers  using  carotid 
restraints,  new  Police  Department  de-escalation  procedures  and  creation  of  an  Office  on  Race  and  Equity." 

US  House  Democrats  Include  $597  Million  For  Police  Reform  In  Spending  Bill 

The  Hill  (7/7,  Elis)  reports,  "House  Democrats  included  a  slew  of  police  reforms,  as  well  as  $596.7  million  in  funding  for 
reform  programs,  in  a  proposed  spending  bill  for  the  2021  fiscal  year,  which  begins  in  October."  The  Hill  adds,  "The  2021 
Commerce,  Justice,  Science  appropriations  bill  includes  $400  million  for  initiatives  that  would  boost  independent  investigations 
of  law  enforcement,  pattern  and  practice  investigations  that  look  for  systemic  problems  in  policing,  community-based 
organizations  seeking  to  improve  law  enforcement  and  other  initiatives.  It  would  also  provide  $50  million  to  train  local  law 
enforcement  on  certain  best  practices,  $77.5  million  to  grant  programs  to  boost  police-community  relations,  $25  million  for 
federal  investigations  into  misconduct  and  $4  million  for  civilian  review  boards." 

US  Lawmakers  Unveil  Bill  To  Defund  Police,  Provide  Reparations 

The  New  York  Post  (7/7,  Nelson)  reports  that  US  Reps.  Ayanna  Pressley  (D-MA)  and  Rashida  Tlaib  (D-MI)  on  Tuesday 
"announced  federal  legislation  to  defund  police  and  set  up  reparations  for  people  who  either  are  black  or  were  harmed  by 
cops."  The  two  lawmakers  announced  the  measure  "on  a  Zoom  call,"  but  it  "has  not  yet  been  introduced."  Said  Tlaib,  "We  can 
start  to  envision  through  this  bill  a  new  version  for  public  safety  -  a  new  vision  for  public  safety,  one  that  protects  and  affirms 
Black  lives." 

The  AP  (7/7,  Stafford)  reports,  "Dubbed  the  BREATHE  Act,  the  legislation  is  the  culmination  of  a  project  led  by  the 
policy  table  of  the  Movement  for  Black  Lives,  a  coalition  of  more  than  150  organizations." 

Minnesota  Lawmakers  Remain  Hopeful  About  Police  Reform  Efforts 

The  Minneapolis  StarTribune  (7/8,  Berkel,  Bierschbach)  reports,  "Minnesota  state  lawmakers  will  get  another  chance  at 
passing  police  accountability  measures  into  law  next  week,  with  Gov.  Tim  Walz  planning  to  call  a  special  legislative  session  for 
the  second  time  this  summer."  The  StarTribune  adds,  "Walz  said  Tuesday  he  is  optimistic  that  lawmakers  can  strike  a  deal  on 
both  a  public  works  spending  package  and  on  police  reforms  in  the  wake  of  the  May  death  of  George  Floyd  at  the  hands  of 


Minneapolis  police  officers."  House  Democrats  "continue  to  push  for  a  sweeping  package  of  changes  to  boost  community-led 
alternatives  to  policing,  ban  warrior-style  training  for  officers  and  raise  the  threshold  for  using  deadly  force  from  'apparent'  to 
'imminent'  threats  to  officers  and  others." 


For  U.S.  Members: 

The  2019-2020  Public  Safety  Officer  Medal  of  Valor  is  the  United  States'  highest  public  safety  honor  that  can  be 
awarded  to  law  enforcement  officers,  emergency  medical  personnel,  and  firefighters.  This  award  honors  federal, 
state,  local,  and  tribal  public  safety  officers  who  have  demonstrated  exceptional  bravery,  risking  serious  injury  or 
death,  in  the  line  of  duty.  The  Bureau  of  Justice  Assistance  is  seeking  nominations  for  the  Medal  of  Valor  now 
through  Friday,  July  31,  2020. 

Public  Safety  Officers  can  be  nominated  for  any  qualifying  event  between  June  1,  2019,  and  May  31,  2020.  Public 
Safety  Officers  must  be  nominated  by  the  heads  of  their  agencies  by  July  31,  2020,  at  11:59  p.m.  ET  to  be 
considered  for  this  award.  Agency  heads  may  submit  multiple  nominations  to  honor  several  officers  or  to  honor 
one  officer  for  multiple  separate  events.  Nomination  guidelines  and  stories  of  past  recipients  can  be  found  on 
the  Medal  of  Valor  website. 
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CRIME  &  DRUGS 

Black  Americans  Report  Hate  Crimes,  Violence  In  Wake  Of  Floyd  Protests 

USA  Today  (7/7,  Philimon)  reports  that  a  "range  of  disturbing  incidents  have  happened  since  George  Floyd's  death  and 
subsequent  protests  against  racism  and  police  brutality."  In  Illinois,  for  example,  "a  man  was  charged  with  a  hate  crime  for 
allegedly  riding  his  motorcycle  into  a  protest  and  hitting  two  people,"  and  "authorities  say  a  KKK  leader  tried  to  run  his  car 
through  a  group  of  peaceful  protesters  in  Virginia." 

The  Washington  Examiner  (7/7,  Smith),  meanwhile,  reports  that  "two  white  residents  of  Martinez,  California,  who 
painted  over  a  Black  Lives  Matter  mural,  have  been  charged  with  a  hate  crime." 

The  Wall  Street  Journal  (7/7,  Kusisto,  Frosch,  Subscription  Publication)  reports  Floyd's  death  has  also  prompted  the 
reexamination  of  older  cases  by  local  prosecutors. 

New  York  City  Police  Arrest  195  In  Fireworks  Crackdown 

WNBC-TV  New  York  (7/7)  reports,  "Nearly  200  illegal  fireworks  have  been  made  in  New  York  City  in  the  two  weeks  since 
Mayor  Bill  de  Blasio  unveiled  a  multi-agency  task  force  to  crack  down  on  the  problem  amid  an  unprecedented  level  of 
complaints,  officials  said  Tuesday."  WNBC-TV  adds,  "The  mayor  revealed  the  task  force,  comprised  of  10  officers  with  the  NYPD 
Intelligence  Bureau,  12  FDNY  Fire  Marshals  and  20  Sheriffs  Bureau  of  Criminal  Investigation  members,  on  June  23.  Its  primary 
goal:  to  disrupt  illegal  fireworks  supply  chains  via  sting  operations  within  and  outside  New  York  City  -  and  officials  say  the  group 
busted  a  total  of  195  people  since  it  was  established.  It's  not  clear  what  prompted  the  extraordinary  surge  in  illegal  fireworks 
usage,  which  prompted  sleep-deprived  New  Yorkers  to  protest  in  front  of  Gracie  Mansion  one  night  last  month  amid  continued 
booming." 

Protesters  Charged  With  Leaking  Police  Document  In  Iowa 

The  AP  (7/7,  Foley)  reports,  "Prosecutors  in  Iowa  have  filed  a  rarely  used  leak  charge  against  Black  Lives  Matter  protesters 
accused  of  stealing  a  confidential  police  document  and  displaying  it  during  a  television  news  broadcast."  The  AP  adds,  "Two 
protesters  are  charged  with  unauthorized  dissemination  of  intelligence  data,  a  felony  that  carries  up  to  five  years  in  prison.  The 
Iowa  Judicial  Branch  says  it's  only  the  second  time  that  the  charge  has  been  filed  since  2010.  It's  intended  to  punish  officers  and 


others  who  share  information  that  could  undermine  criminal  investigations  or  violate  privacy  protections."  According  to  the  AP, 
"The  document  in  question  was  a  Des  Moines  Police  Department  bulletin  that  officers  and  state  troopers  had  with  them  while 
patrolling  a  July  1  protest  at  the  Iowa  Capitol.  The  bulletin  included  photos  of  suspects  who  were  wanted  in  the  destruction  of  a 
Des  Moines  police  car  during  a  June  20  protest." 

Dutch  Police  Arrest  Six,  Uncover  Makeshift  Torture  Chamber 

The  AP  (7/7,  Corder)  reports,  "Dutch  police  arrested  six  men  after  discovering  sea  containers  that  had  been  converted 
into  a  makeshift  prison  and  sound-proofed  'torture  chamber'  complete  with  a  dentist's  chair,  tools  including  pliers  and  scalpels 
and  handcuffs,  a  high  ranking  officer  announced  Tuesday.  Authorities  said  police  conducted  the  raid  before  the  torture 
chamber  could  be  used  and  alerted  potential  victims,  who  went  into  hiding."  The  AP  adds,  "The  grisly  discovery  was  made  last 
month  by  officers  investigating  leads  generated  by  data  from  encrypted  phones  used  by  criminals.  The  communications 
network  was  cracked  recently  by  French  police.  Detectives  in  Britain  and  the  Netherlands  have  already  arrested  hundreds  of 
suspects  based  on  the  encrypted  messages."  According  to  the  AP,  "Tuesday's  announcement  gave  a  chilling  insight  into  the 
increasingly  violent  Dutch  criminal  underworld,  which  is  involved  in  the  large  scale  production  and  trafficking  of  drugs." 

TECHNOLOGY 


German  Authorities  Seize  Server  Hosting  "BlueLeaks"  Data  Dump 

PCMag  (7/7,  Kan)  reports,  "German  authorities  have  confiscated  a  server  hosting  the  "BlueLeaks"  data  dump,  a  269GB 
trove  of  internal  police  documents  that  leaked  last  month."  According  to  PCMag,  "The  Wikileaks-style  group  Distributed  Denial 
of  Secrets  (DDOS)  had  been  using  the  server  to  enable  the  public  to  download  the  files,  but  prosecutors  in  Germany  recently 
seized  it,  according  to  Emma  Best,  a  journalist  and  co-founder  of  the  group.  DDOS  says  it  obtained  the  files  from  the  'hacktivist' 
collective  Anonymous,  and  then  made  the  files  searchable  on  a  dedicated  website  on  July  19.  However,  the  site  now  appears  to 
be  down."  Best  said  "German  authorities  seized  the  'primary  public  download  server'  hosting  the  data  dump  without  supplying 
an  explanation.  The  hosting  provider  has  only  said  the  takedown  came  from  the  'department  of  public  prosecution  Zwickau,' 
which  didn't  immediately  respond  to  a  request  for  comment." 

TUESDAY'S  LEAD  STORIES 


•  Qualified  Immunity  At  Forefront  Of  Policing  Debate 

•  Door  Of  Portland,  Oregon  Federal  Courthouse  Shattered,  Fireworks  Exploded  Inside 

•  New  Mexico  Militia  Was  Involved  In  June  Shooting  Incident  In  Albuquerque 

Subscriber  Tools 

•  Change  Email  Address 

•  Send  Feedback 

•  Unsubscribe 

•  Email  Help 

•  Archives 

The  Lead  is  a  daily  news  briefing  selected  from  thousands  of  sources  by  the  editors  of  Bulletin  Media.  Neither  Bulletin  Media  nor  the 
International  Association  of  Chiefs  of  Police  is  liable  for  the  use  of  or  reliance  on  any  information  contained  in  this  briefing.  The  presence  of 
articles  and/or  advertising  does  not  endorse,  nor  imply  endorsement  of,  any  products  or  services  by  the  IACP. 

This  complimentary  copy  of  The  Lead  was  sent  to  sean.gleason@cookcountyil.gov  as  a  member  benefit.  To  see  how  we  protect  our  data,  or  for 
any  questions  on  data  access,  view  Bulletin  Media's  privacy  policy. 

For  information  about  other  member  benefits,  please  contact  the  IACP  at  membership@theiacp.org  or  1.800.THE  IACP. 

International  Association  of  Chiefs  of  Police  |  44  Canal  Center  Plaza  Suite  200  |  Alexandria,  VA  22314 
Copyright  ©  2020  by  Bulletin  Media  |  11190  Sunrise  Valley  Drive  Suite  20  |  Reston,  VA  20191 


Fw:  lACP's  The  Lead:  Some  US  States  Consider  Police  Licensing. 

To:  2020  Criminal  Investigations  Supervisors,  Scott  Lefko  (Sheriff) 

Sent:  July  8,  2020  1 :1 1 :54  PM  CDT 

Received:  July  8,  2020  1 :1 1 :56  PM  CDT 


Fw:  lACP's  The  Lead:  Some  US  States  Consider  Police  Licensing. 

To:  2020  Criminal  Investigations  Supervisors 

Sent:  July  8,  2020  1 :1 1 :54  PM  CDT 

Received:  July  8,  2020  1 :1 1 :56  PM  CDT 


Fw:  lACP's  The  Lead:  Some  US  States  Consider  Police  Licensing. 

To:  2020  Criminal  Investigations  Supervisors,  Mike  Grimes 

Sent:  July  8,  2020  1 :1 1 :54  PM  CDT 

Received:  July  8,  2020  1 :1 2:04  PM  CDT 


Fw:  lACP's  The  Lead:  Some  US  States  Consider  Police  Licensing. 

To:  2020  Criminal  Investigations  Supervisors,  Michael  Dwyer  (Sheriff) 

Sent:  July  8,  2020  1 :1 1 :54  PM  CDT 

Received:  July  8,  2020  1 :1 1 :56  PM  CDT 


lACP's  The  Lead:  Minnesota  US  Attorney  Announces  Task  Force  To  Curb  Gun 
Violence. 


From:  The  IACP  <TheLead@iacp. bulletinmedia.com> 

To:  jennifer.warren@cookcountyil.gov,  Jennifer  Warren  (Sheriff) 

Jennifer.  warren@cookcountyil.gov> 

Sent:  July  9,  2020  7:07:59  AM  CDT 

Received:  July  9,  2020  7:08:13  AM  CDT 


External  Message  Disclaimer 

This  message  originated  from  an  external  source.  Please  use  proper  judgment  and  caution  when 

If  you  are  unable  to  see  the  message  or  images  below,  click  here  to  view 


POLICING  &  POLICY 


Minnesota  US  Attorney  Announces  Task  Force  To  Curb 
Gun  Violence 

The  Minneapolis  StarTribune  (7/8)  reports,  "U.S.  Attorney  Erica 
MacDonald  is  mobilizing  a  multiagency  command  center  for  a  new  task 
Force  aimed  at  curbing  "an  extraordinary  spike"  in  violence  in  the  Twin 
□ties  that  has  been  on  the  rise  since  Memorial  Day."  MacDonald  on 
Wednesday  "outlined  a  30-day  operation  that  will  deploy  state  and 
Federal  law  enforcement  across  a  dozen  agencies  in  response  to  a  spike 
n  gun  violence  and  other  crimes." 

The  St.  Paul  (MN)  Pioneer  Press  (7/8,  Harville)  reports,  "The 
Twin  Cities  Violent  Crime  Task  Force  will  work  with  additional  state  and 
Federal  resources  to  help  local  law  enforcement  investigate,  arrest  and 
prosecute  individuals  contributing  to  the  gun  violence  in  Minneapolis 
and  St.  Paul.  As  of  Tuesday  this  year,  101  people  have  been  shot  in  St.  Paul,  including  some  fatally,  according  to  police.  That's 
compared  with  70  as  of  the  end  of  June  2019.  'Law  enforcement  partners  will  utilize  the  task  force  to  maximize  intelligence 
gathering  and  information  sharing  capabilities  to  ensure  swift  and  precise  identification  of  those  individuals  who  are 
perpetrating  violence,'  the  U.S.  Attorney's  office  said  in  a  statement.  MacDonald  stressed  that  the  goal  of  the  task  force  is  'not 
to  flood  our  communities  with  law  enforcement,'  but  rather  to  create  a  way  for  community  members  and  city  leaders  to 
collaborate  with  law  enforcement  while  putting  a  stop  to  gun  violence." 


US  Launches  Anti-Crime  Initiative  In  Kansas  City,  Missouri 


The  Washington  Times  (7/8,  Boyer)  reports  the  Administration  is  "surging  federal  law-enforcement  agents  into  Kansas 
City,  Missouri,  to  fight  a  wave  of  violent  crime,  the  White  House  said  Wednesday."  Attorney  General  Barr  is  "launching  the 
operation  within  the  next  10  days  with  FBI  agents,  U.S.  marshals,  Drug  Enforcement  Administration  agents  and  officials  from 
the  Bureau  of  Alcohol,  Tobacco,  Firearms  and  Explosives  to  help  suppress  what  the  White  House  called  a  'tragic'  rise  in 
violence." 

KCTV-TV  Kansas  City,  MO  (7/8,  Smith)  reports  that  "Operation:  Legend"  is  "being  touted  by  the  Department  of  Justice 
as  a  response  to  the  surge  in  violent  crime  in  Kansas  City.  The  focus  of  the  new  initiative  is  to  increase  the  federal  law 
enforcement  present  in  the  city.  Press  Secretary  Kayleigh  McEnany  said  the  new  plan  was  inspired  by  Mayor  Quinton  Lucas' 
letter  to  Missouri  Governor  Mike  Parson  where  Lucas  wrote  that  Kansas  City  was  'at  a  crisis  point.'  The  letter,  originally  sent 
July  3,  was  looking  for  Parson  to  convene  a  special  session  of  the  Missouri  legislature  focused  on  growing  crime  in  Missouri 
cities." 

US  Sen.  Tim  Scott  Says  Police  Reform  Bill  Is  Not  Dead 

The  Washington  Times  (7/8,  Mordock)  reports  Sen.  Tim  Scott  (R-SC)  said  Wednesday  a  bill  he  authored  on  police  reform 
"is  not  dead  and  he  expects  an  agreement  with  the  Democrat-controlled  House  in  the  next  few  weeks."  Speaking  with  reporters 
at  a  press  event  with  Attorney  General  Barr,  "Scott  said  he  has  talked  with  House  Democrats  about  reaching  a  deal."  Said  the 
senator,  "Folks  are  now  calling  me  about  the  legislation  from  the  other  side,  suggesting  perhaps  it  is  not  dead.  We  may  have  a 
Lazarus  moment." 

New  Mexico  Mandates  Police  Body  Cameras 

The  AP  (7/8)  reports,  "New  Mexico  will  require  that  all  state  and  local  police  officers  wear  body  cameras  in  response  to 
concern  about  excessive  use  of  force  by  law  enforcement,  under  a  bill  signed  Wednesday  by  Gov.  Michelle  Lujan  Grisham."  The 
AP  adds,  "The  reforms  apply  to  local  and  state  law  enforcement  officers  with  the  exception  of  tribal  governments.  Law 
enforcement  agencies  must  archive  body  camera  footage  for  at  least  120  days."  The  state  legislature  "approved  the  policing 
reforms  during  a  four-day  special  session  in  June."  The  AP  adds,  "Police  agencies  that  flout  the  new  body-camera  requirement 
can  sued  for  withholding  evidence." 

Colorado  City  Passes  Resolution  Shielding  Officers  From  Portion  Of  State  Reform  Law 

The  Denver  Post  (7/8,  Aguilar)  reports,  "Just  weeks  after  Colorado  passed  a  sweeping  police  reform  law,  Greenwood 
Village  has  approved  a  measure  that  ensures  its  officers  aren't  on  the  hook  financially  if  they  mistreat  or  harm  a  citizen." 
Greenwood  Village  council  members  "unanimously  passed  a  resolution  Monday  saying  the  city  will  never  find  its  officers  have 
acted  in  bad  faith,"  and  "that  effectively  shields  them  from  having  to  face  personal  financial  liability  for  misconduct  on  the  job  - 
contrary  to  a  key  stipulation  of  Senate  Bill  217,  which  became  law  last  month.  'The  intent  of  Council's  resolution  was  simply  to 
inform  its  officers  that  as  their  employer,  they  would  not  make  such  a  (bad-faith)  finding  no  matter  what,'  Greenwood  Village 
city  attorney  Tonya  Haas  Davidson  wrote  in  an  email  Wednesday.  'Nowhere  in  the  law  is  an  employer  ever  required  to  make  a 
finding  of  bad  faith.'" 

Chicago  Police  Announce  Formation  Of  Citywide  Unit  To  Fight  Violent  Crime 

The  Chicago  Sun-Times  (7/8)  reports,  "Chicago  police  announced  Tuesday  it  will  create  a  citywide  violent  crime  unit  after 
three  consecutive  weekends  with  at  least  65  people  shot  and  multiple  children  killed.  The  specialized  unit  is  meant  'to  tackle 
violent  crime  and  create  community  partnerships  in  some  of  our  most  challenging  areas,'  the  department  said.  'The  ultimate 
goal  of  the  Chicago  Police  Department's  organizational  restructuring  that  began  earlier  this  year  has  always  been  to  bolster 
police  resources  under  the  authority  of  district  commanders,  while  also  being  able  to  address  spikes  in  violent  crime  citywide,' 
the  department  said."  The  Sun-Times  adds,  "Once  implemented,  the  new  unit  will  'impact'  gun,  saturation  and  gang 
enforcement  teams  in  each  of  the  city's  five  police  Areas,  the  department  said.  In  the  meantime,  police  are  bolstering  the 
Summer  Mobile  Patrol  Unit,  a  task  force  of  100  officers  focusing  on  high-crime  areas." 


After  George  Floyd's  death  and  the  response  that  followed,  police  leaders,  community  members,  and  elected 
officials  in  the  United  States  and  around  the  world  are  looking  for  collaborative,  constructive  ways  to  move  public 
safety  efforts  forward.  The  IACP  has  launched  a  new  Community-Police  Engagement  resource  page  featuring  a 
variety  of  tools  that  provide  policy  considerations  and  tangible  strategies  to  support  police  and  communities  in 
their  efforts  to  engage  in  productive  dialogue,  form  strong  partnerships,  and  identify  meaningful  solutions. 

Topics  include  community  policing;  bias  free  policing;  use  of  force;  leadership  and  culture;  and  recruitment  and 
promotional  testing.  At  a  time  when  agencies  are  looking  to  assess  their  policies  and  procedures  and  develop 
new  initiatives  to  maximize  community-police  engagement,  these  tools  provide  a  meaningful  base  to  help  public 
safety  stakeholders  develop  a  strong,  consistent  foundation. 
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CRIME  &  DRUGS 


Driver  Charged  With  Vehicular  Homicide  In  Death  Of  Seattle  Protester 

The  Washington  Post  (7/8,  Guarino)  reports,  "A  man  who  allegedly  struck  Black  Lives  Matter  protesters  in  Seattle  with  his 
car,  killing  one,  was  charged  with  reckless  driving,  vehicular  assault  and  vehicular  homicide  by  the  King  County  Prosecuting 
Attorney's  Office  on  Wednesday.  Washington  State  Patrol  and  the  FBI  are  investigating  the  case,  a  prominent  and  fatal  example 
of  recent  car  attacks  on  demonstrators."  The  Post  adds,  "When  protesters  gathered  for  a  Black  Femme  March  on  Interstate  5 
on  July  3,  it  was  the  19th  consecutive  night  activists  had  done  so,  according  to  the  state  patrol.  Near  midnight,  the  patrol  closed 
a  section  of  the  interstate  for  the  demonstration.  After  1  a.m.,  a  white  Jaguar,  seen  on  security  video  entering  the  highway 
through  an  off-ramp,  drove  through  the  group  at  high  speed,  authorities  said.  The  car  struck  two  people  -  Summer  Taylor,  a  24- 
year-old  Seattle  resident,  and  Diaz  Love,  32  -  then  fled  the  scene,  speeding  down  the  highway." 

The  New  York  Times  (7/8,  Waller,  Paybarah)  reports  that  Dawit  Kelete,  27,  "is  being  held  with  bail  set  at  $1.2  million 
and  is  expected  to  remain  in  jail,  the  King  County  Prosecuting  Attorney's  Office  said.  Two  of  the  charges,  vehicular  homicide  and 
vehicular  assault,  are  felonies,  a  spokesman  for  the  prosecuting  attorney's  office  said.  Mr.  Kelete  could  face  more  than  13  years 
in  prison,  said  the  spokesman,  Casey  McNerthney."  The  Times  adds,  "The  Washington  State  Patrol  and  the  F.B.I.  were  still 
investigating  the  matter,  and  Mr.  Kelete  could  face  additional  charges,  according  to  a  statement  from  the  prosecutor's  office." 

Crews  Of  ATM  Thieves  Using  Trucks  As  Battering  Rams  Inside  Baltimore,  Maryland  Businesses 

The  Baltimore  Sun  (7/8,  Fenton)  reports,  "Sometimes,  they  operate  with  the  speed  and  precision  of  a  NASCAR  pit  crew  - 
prying  open  the  locked  steel  gates  and  doors  of  small  businesses  around  Baltimore,  then  lifting  away  ATMs  and  hurrying  them 
to  a  waiting  pickup  truck  or  van.  Other  times,  the  thieves  use  vehicles  -  typically  stolen  -  as  battering  rams  to  force  entry.  They 
crash  through  storefronts  to  commit  a  small  bank  robbery  that  does  not  require  holding  up  a  teller."  The  Sun  adds,  "The  chaotic 
crimes  have  continued  on  and  off  for  months,  with  small  businesses  and  one  ATM  distributor  saying  it's  a  new  and  alarming 
trend.  During  the  course  of  one  hour  as  the  sun  came  up  June  27,  three  stores  were  hit  in  west,  northeast  and  midtown 
Baltimore,  including  someone  ramming  into  a  gas  station  on  Moravia  Road.  They've  used  different  methods  and  vehicles, 
causing  police  to  believe  it's  not  just  the  work  of  one  crew  and  that  others  are  getting  in  on  the  crime." 

Mexican  Drug  Cartel  Attacks  Public  Officials 

The  Wall  Street  Journal  (7/8,  Montes,  de  Cordoba,  Subscription  Publication)  reports  on  the  Jalisco  New  Generation  Cartel, 
saying  that  it  is  the  most  important  cartel  in  Mexico  and  has  mounted  direct  assaults  on  Mexican  officials  and  law  enforcement. 
According  to  the  Journal,  the  group  is  responsible  for  the  deaths  of  over  100  officials.  The  US  Drug  Enforcement  Administration 
is  offering  $10  million  for  information  leading  to  the  arrest  of  the  group's  leader  Nemesio  Oseguera. 
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Minnesota  US  Attorney  Announces  Task  Force  To  Curb 
Gun  Violence 

The  Minneapolis  StarTribune  (7/8)  reports,  "U.S.  Attorney  Erica 
MacDonald  is  mobilizing  a  multiagency  command  center  for  a  new  task 
Force  aimed  at  curbing  "an  extraordinary  spike"  in  violence  in  the  Twin 
□ties  that  has  been  on  the  rise  since  Memorial  Day."  MacDonald  on 
Wednesday  "outlined  a  30-day  operation  that  will  deploy  state  and 
Federal  law  enforcement  across  a  dozen  agencies  in  response  to  a  spike 
n  gun  violence  and  other  crimes." 

The  St.  Paul  (MN)  Pioneer  Press  (7/8,  Harville)  reports,  "The 
Twin  Cities  Violent  Crime  Task  Force  will  work  with  additional  state  and 
Federal  resources  to  help  local  law  enforcement  investigate,  arrest  and 
prosecute  individuals  contributing  to  the  gun  violence  in  Minneapolis 
and  St.  Paul.  As  of  Tuesday  this  year,  101  people  have  been  shot  in  St.  Paul,  including  some  fatally,  according  to  police.  That's 
compared  with  70  as  of  the  end  of  June  2019.  'Law  enforcement  partners  will  utilize  the  task  force  to  maximize  intelligence 
gathering  and  information  sharing  capabilities  to  ensure  swift  and  precise  identification  of  those  individuals  who  are 
perpetrating  violence,'  the  U.S.  Attorney's  office  said  in  a  statement.  MacDonald  stressed  that  the  goal  of  the  task  force  is  'not 
to  flood  our  communities  with  law  enforcement,'  but  rather  to  create  a  way  for  community  members  and  city  leaders  to 
collaborate  with  law  enforcement  while  putting  a  stop  to  gun  violence." 


US  Launches  Anti-Crime  Initiative  In  Kansas  City,  Missouri 


The  Washington  Times  (7/8,  Boyer)  reports  the  Administration  is  "surging  federal  law-enforcement  agents  into  Kansas 
City,  Missouri,  to  fight  a  wave  of  violent  crime,  the  White  House  said  Wednesday."  Attorney  General  Barr  is  "launching  the 
operation  within  the  next  10  days  with  FBI  agents,  U.S.  marshals,  Drug  Enforcement  Administration  agents  and  officials  from 
the  Bureau  of  Alcohol,  Tobacco,  Firearms  and  Explosives  to  help  suppress  what  the  White  House  called  a  'tragic'  rise  in 
violence." 

KCTV-TV  Kansas  City,  MO  (7/8,  Smith)  reports  that  "Operation:  Legend"  is  "being  touted  by  the  Department  of  Justice 
as  a  response  to  the  surge  in  violent  crime  in  Kansas  City.  The  focus  of  the  new  initiative  is  to  increase  the  federal  law 
enforcement  present  in  the  city.  Press  Secretary  Kayleigh  McEnany  said  the  new  plan  was  inspired  by  Mayor  Quinton  Lucas' 
letter  to  Missouri  Governor  Mike  Parson  where  Lucas  wrote  that  Kansas  City  was  'at  a  crisis  point.'  The  letter,  originally  sent 
July  3,  was  looking  for  Parson  to  convene  a  special  session  of  the  Missouri  legislature  focused  on  growing  crime  in  Missouri 
cities." 

US  Sen.  Tim  Scott  Says  Police  Reform  Bill  Is  Not  Dead 

The  Washington  Times  (7/8,  Mordock)  reports  Sen.  Tim  Scott  (R-SC)  said  Wednesday  a  bill  he  authored  on  police  reform 
"is  not  dead  and  he  expects  an  agreement  with  the  Democrat-controlled  House  in  the  next  few  weeks."  Speaking  with  reporters 
at  a  press  event  with  Attorney  General  Barr,  "Scott  said  he  has  talked  with  House  Democrats  about  reaching  a  deal."  Said  the 
senator,  "Folks  are  now  calling  me  about  the  legislation  from  the  other  side,  suggesting  perhaps  it  is  not  dead.  We  may  have  a 
Lazarus  moment." 

New  Mexico  Mandates  Police  Body  Cameras 

The  AP  (7/8)  reports,  "New  Mexico  will  require  that  all  state  and  local  police  officers  wear  body  cameras  in  response  to 
concern  about  excessive  use  of  force  by  law  enforcement,  under  a  bill  signed  Wednesday  by  Gov.  Michelle  Lujan  Grisham."  The 
AP  adds,  "The  reforms  apply  to  local  and  state  law  enforcement  officers  with  the  exception  of  tribal  governments.  Law 
enforcement  agencies  must  archive  body  camera  footage  for  at  least  120  days."  The  state  legislature  "approved  the  policing 
reforms  during  a  four-day  special  session  in  June."  The  AP  adds,  "Police  agencies  that  flout  the  new  body-camera  requirement 
can  sued  for  withholding  evidence." 

Colorado  City  Passes  Resolution  Shielding  Officers  From  Portion  Of  State  Reform  Law 

The  Denver  Post  (7/8,  Aguilar)  reports,  "Just  weeks  after  Colorado  passed  a  sweeping  police  reform  law,  Greenwood 
Village  has  approved  a  measure  that  ensures  its  officers  aren't  on  the  hook  financially  if  they  mistreat  or  harm  a  citizen." 
Greenwood  Village  council  members  "unanimously  passed  a  resolution  Monday  saying  the  city  will  never  find  its  officers  have 
acted  in  bad  faith,"  and  "that  effectively  shields  them  from  having  to  face  personal  financial  liability  for  misconduct  on  the  job  - 
contrary  to  a  key  stipulation  of  Senate  Bill  217,  which  became  law  last  month.  'The  intent  of  Council's  resolution  was  simply  to 
inform  its  officers  that  as  their  employer,  they  would  not  make  such  a  (bad-faith)  finding  no  matter  what,'  Greenwood  Village 
city  attorney  Tonya  Haas  Davidson  wrote  in  an  email  Wednesday.  'Nowhere  in  the  law  is  an  employer  ever  required  to  make  a 
finding  of  bad  faith.'" 

Chicago  Police  Announce  Formation  Of  Citywide  Unit  To  Fight  Violent  Crime 

The  Chicago  Sun-Times  (7/8)  reports,  "Chicago  police  announced  Tuesday  it  will  create  a  citywide  violent  crime  unit  after 
three  consecutive  weekends  with  at  least  65  people  shot  and  multiple  children  killed.  The  specialized  unit  is  meant  'to  tackle 
violent  crime  and  create  community  partnerships  in  some  of  our  most  challenging  areas,'  the  department  said.  'The  ultimate 
goal  of  the  Chicago  Police  Department's  organizational  restructuring  that  began  earlier  this  year  has  always  been  to  bolster 
police  resources  under  the  authority  of  district  commanders,  while  also  being  able  to  address  spikes  in  violent  crime  citywide,' 
the  department  said."  The  Sun-Times  adds,  "Once  implemented,  the  new  unit  will  'impact'  gun,  saturation  and  gang 
enforcement  teams  in  each  of  the  city's  five  police  Areas,  the  department  said.  In  the  meantime,  police  are  bolstering  the 
Summer  Mobile  Patrol  Unit,  a  task  force  of  100  officers  focusing  on  high-crime  areas." 


After  George  Floyd's  death  and  the  response  that  followed,  police  leaders,  community  members,  and  elected 
officials  in  the  United  States  and  around  the  world  are  looking  for  collaborative,  constructive  ways  to  move  public 
safety  efforts  forward.  The  IACP  has  launched  a  new  Community-Police  Engagement  resource  page  featuring  a 
variety  of  tools  that  provide  policy  considerations  and  tangible  strategies  to  support  police  and  communities  in 
their  efforts  to  engage  in  productive  dialogue,  form  strong  partnerships,  and  identify  meaningful  solutions. 

Topics  include  community  policing;  bias  free  policing;  use  of  force;  leadership  and  culture;  and  recruitment  and 
promotional  testing.  At  a  time  when  agencies  are  looking  to  assess  their  policies  and  procedures  and  develop 
new  initiatives  to  maximize  community-police  engagement,  these  tools  provide  a  meaningful  base  to  help  public 
safety  stakeholders  develop  a  strong,  consistent  foundation. 

Learn  more. 


Connect  with  the  IACP 
online: 


IACP  Event  Calendar: 


CRIME  &  DRUGS 


Driver  Charged  With  Vehicular  Homicide  In  Death  Of  Seattle  Protester 

The  Washington  Post  (7/8,  Guarino)  reports,  "A  man  who  allegedly  struck  Black  Lives  Matter  protesters  in  Seattle  with  his 
car,  killing  one,  was  charged  with  reckless  driving,  vehicular  assault  and  vehicular  homicide  by  the  King  County  Prosecuting 
Attorney's  Office  on  Wednesday.  Washington  State  Patrol  and  the  FBI  are  investigating  the  case,  a  prominent  and  fatal  example 
of  recent  car  attacks  on  demonstrators."  The  Post  adds,  "When  protesters  gathered  for  a  Black  Femme  March  on  Interstate  5 
on  July  3,  it  was  the  19th  consecutive  night  activists  had  done  so,  according  to  the  state  patrol.  Near  midnight,  the  patrol  closed 
a  section  of  the  interstate  for  the  demonstration.  After  1  a.m.,  a  white  Jaguar,  seen  on  security  video  entering  the  highway 
through  an  off-ramp,  drove  through  the  group  at  high  speed,  authorities  said.  The  car  struck  two  people  -  Summer  Taylor,  a  24- 
year-old  Seattle  resident,  and  Diaz  Love,  32  -  then  fled  the  scene,  speeding  down  the  highway." 

The  New  York  Times  (7/8,  Waller,  Paybarah)  reports  that  Dawit  Kelete,  27,  "is  being  held  with  bail  set  at  $1.2  million 
and  is  expected  to  remain  in  jail,  the  King  County  Prosecuting  Attorney's  Office  said.  Two  of  the  charges,  vehicular  homicide  and 
vehicular  assault,  are  felonies,  a  spokesman  for  the  prosecuting  attorney's  office  said.  Mr.  Kelete  could  face  more  than  13  years 
in  prison,  said  the  spokesman,  Casey  McNerthney."  The  Times  adds,  "The  Washington  State  Patrol  and  the  F.B.I.  were  still 
investigating  the  matter,  and  Mr.  Kelete  could  face  additional  charges,  according  to  a  statement  from  the  prosecutor's  office." 

Crews  Of  ATM  Thieves  Using  Trucks  As  Battering  Rams  Inside  Baltimore,  Maryland  Businesses 

The  Baltimore  Sun  (7/8,  Fenton)  reports,  "Sometimes,  they  operate  with  the  speed  and  precision  of  a  NASCAR  pit  crew  - 
prying  open  the  locked  steel  gates  and  doors  of  small  businesses  around  Baltimore,  then  lifting  away  ATMs  and  hurrying  them 
to  a  waiting  pickup  truck  or  van.  Other  times,  the  thieves  use  vehicles  -  typically  stolen  -  as  battering  rams  to  force  entry.  They 
crash  through  storefronts  to  commit  a  small  bank  robbery  that  does  not  require  holding  up  a  teller."  The  Sun  adds,  "The  chaotic 
crimes  have  continued  on  and  off  for  months,  with  small  businesses  and  one  ATM  distributor  saying  it's  a  new  and  alarming 
trend.  During  the  course  of  one  hour  as  the  sun  came  up  June  27,  three  stores  were  hit  in  west,  northeast  and  midtown 
Baltimore,  including  someone  ramming  into  a  gas  station  on  Moravia  Road.  They've  used  different  methods  and  vehicles, 
causing  police  to  believe  it's  not  just  the  work  of  one  crew  and  that  others  are  getting  in  on  the  crime." 

Mexican  Drug  Cartel  Attacks  Public  Officials 

The  Wall  Street  Journal  (7/8,  Montes,  de  Cordoba,  Subscription  Publication)  reports  on  the  Jalisco  New  Generation  Cartel, 
saying  that  it  is  the  most  important  cartel  in  Mexico  and  has  mounted  direct  assaults  on  Mexican  officials  and  law  enforcement. 
According  to  the  Journal,  the  group  is  responsible  for  the  deaths  of  over  100  officials.  The  US  Drug  Enforcement  Administration 
is  offering  $10  million  for  information  leading  to  the  arrest  of  the  group's  leader  Nemesio  Oseguera. 
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POLICING  &  POLICY 


Minnesota  US  Attorney  Announces  Task  Force  To  Curb 
Gun  Violence 

The  Minneapolis  StarTribune  (7/8)  reports,  "U.S.  Attorney  Erica 
MacDonald  is  mobilizing  a  multiagency  command  center  for  a  new  task 
Force  aimed  at  curbing  "an  extraordinary  spike"  in  violence  in  the  Twin 
□ties  that  has  been  on  the  rise  since  Memorial  Day."  MacDonald  on 
Wednesday  "outlined  a  30-day  operation  that  will  deploy  state  and 
Federal  law  enforcement  across  a  dozen  agencies  in  response  to  a  spike 
n  gun  violence  and  other  crimes." 

The  St.  Paul  (MN)  Pioneer  Press  (7/8,  Harville)  reports,  "The 
Twin  Cities  Violent  Crime  Task  Force  will  work  with  additional  state  and 
Federal  resources  to  help  local  law  enforcement  investigate,  arrest  and 
prosecute  individuals  contributing  to  the  gun  violence  in  Minneapolis 
and  St.  Paul.  As  of  Tuesday  this  year,  101  people  have  been  shot  in  St.  Paul,  including  some  fatally,  according  to  police.  That's 
compared  with  70  as  of  the  end  of  June  2019.  'Law  enforcement  partners  will  utilize  the  task  force  to  maximize  intelligence 
gathering  and  information  sharing  capabilities  to  ensure  swift  and  precise  identification  of  those  individuals  who  are 
perpetrating  violence,'  the  U.S.  Attorney's  office  said  in  a  statement.  MacDonald  stressed  that  the  goal  of  the  task  force  is  'not 
to  flood  our  communities  with  law  enforcement,'  but  rather  to  create  a  way  for  community  members  and  city  leaders  to 
collaborate  with  law  enforcement  while  putting  a  stop  to  gun  violence." 


US  Launches  Anti-Crime  Initiative  In  Kansas  City,  Missouri 


The  Washington  Times  (7/8,  Boyer)  reports  the  Administration  is  "surging  federal  law-enforcement  agents  into  Kansas 
City,  Missouri,  to  fight  a  wave  of  violent  crime,  the  White  House  said  Wednesday."  Attorney  General  Barr  is  "launching  the 
operation  within  the  next  10  days  with  FBI  agents,  U.S.  marshals,  Drug  Enforcement  Administration  agents  and  officials  from 
the  Bureau  of  Alcohol,  Tobacco,  Firearms  and  Explosives  to  help  suppress  what  the  White  House  called  a  'tragic'  rise  in 
violence." 

KCTV-TV  Kansas  City,  MO  (7/8,  Smith)  reports  that  "Operation:  Legend"  is  "being  touted  by  the  Department  of  Justice 
as  a  response  to  the  surge  in  violent  crime  in  Kansas  City.  The  focus  of  the  new  initiative  is  to  increase  the  federal  law 
enforcement  present  in  the  city.  Press  Secretary  Kayleigh  McEnany  said  the  new  plan  was  inspired  by  Mayor  Quinton  Lucas' 
letter  to  Missouri  Governor  Mike  Parson  where  Lucas  wrote  that  Kansas  City  was  'at  a  crisis  point.'  The  letter,  originally  sent 
July  3,  was  looking  for  Parson  to  convene  a  special  session  of  the  Missouri  legislature  focused  on  growing  crime  in  Missouri 
cities." 

US  Sen.  Tim  Scott  Says  Police  Reform  Bill  Is  Not  Dead 

The  Washington  Times  (7/8,  Mordock)  reports  Sen.  Tim  Scott  (R-SC)  said  Wednesday  a  bill  he  authored  on  police  reform 
"is  not  dead  and  he  expects  an  agreement  with  the  Democrat-controlled  House  in  the  next  few  weeks."  Speaking  with  reporters 
at  a  press  event  with  Attorney  General  Barr,  "Scott  said  he  has  talked  with  House  Democrats  about  reaching  a  deal."  Said  the 
senator,  "Folks  are  now  calling  me  about  the  legislation  from  the  other  side,  suggesting  perhaps  it  is  not  dead.  We  may  have  a 
Lazarus  moment." 

New  Mexico  Mandates  Police  Body  Cameras 

The  AP  (7/8)  reports,  "New  Mexico  will  require  that  all  state  and  local  police  officers  wear  body  cameras  in  response  to 
concern  about  excessive  use  of  force  by  law  enforcement,  under  a  bill  signed  Wednesday  by  Gov.  Michelle  Lujan  Grisham."  The 
AP  adds,  "The  reforms  apply  to  local  and  state  law  enforcement  officers  with  the  exception  of  tribal  governments.  Law 
enforcement  agencies  must  archive  body  camera  footage  for  at  least  120  days."  The  state  legislature  "approved  the  policing 
reforms  during  a  four-day  special  session  in  June."  The  AP  adds,  "Police  agencies  that  flout  the  new  body-camera  requirement 
can  sued  for  withholding  evidence." 

Colorado  City  Passes  Resolution  Shielding  Officers  From  Portion  Of  State  Reform  Law 

The  Denver  Post  (7/8,  Aguilar)  reports,  "Just  weeks  after  Colorado  passed  a  sweeping  police  reform  law,  Greenwood 
Village  has  approved  a  measure  that  ensures  its  officers  aren't  on  the  hook  financially  if  they  mistreat  or  harm  a  citizen." 
Greenwood  Village  council  members  "unanimously  passed  a  resolution  Monday  saying  the  city  will  never  find  its  officers  have 
acted  in  bad  faith,"  and  "that  effectively  shields  them  from  having  to  face  personal  financial  liability  for  misconduct  on  the  job  - 
contrary  to  a  key  stipulation  of  Senate  Bill  217,  which  became  law  last  month.  'The  intent  of  Council's  resolution  was  simply  to 
inform  its  officers  that  as  their  employer,  they  would  not  make  such  a  (bad-faith)  finding  no  matter  what,'  Greenwood  Village 
city  attorney  Tonya  Haas  Davidson  wrote  in  an  email  Wednesday.  'Nowhere  in  the  law  is  an  employer  ever  required  to  make  a 
finding  of  bad  faith.'" 

Chicago  Police  Announce  Formation  Of  Citywide  Unit  To  Fight  Violent  Crime 

The  Chicago  Sun-Times  (7/8)  reports,  "Chicago  police  announced  Tuesday  it  will  create  a  citywide  violent  crime  unit  after 
three  consecutive  weekends  with  at  least  65  people  shot  and  multiple  children  killed.  The  specialized  unit  is  meant  'to  tackle 
violent  crime  and  create  community  partnerships  in  some  of  our  most  challenging  areas,'  the  department  said.  'The  ultimate 
goal  of  the  Chicago  Police  Department's  organizational  restructuring  that  began  earlier  this  year  has  always  been  to  bolster 
police  resources  under  the  authority  of  district  commanders,  while  also  being  able  to  address  spikes  in  violent  crime  citywide,' 
the  department  said."  The  Sun-Times  adds,  "Once  implemented,  the  new  unit  will  'impact'  gun,  saturation  and  gang 
enforcement  teams  in  each  of  the  city's  five  police  Areas,  the  department  said.  In  the  meantime,  police  are  bolstering  the 
Summer  Mobile  Patrol  Unit,  a  task  force  of  100  officers  focusing  on  high-crime  areas." 


After  George  Floyd's  death  and  the  response  that  followed,  police  leaders,  community  members,  and  elected 
officials  in  the  United  States  and  around  the  world  are  looking  for  collaborative,  constructive  ways  to  move  public 
safety  efforts  forward.  The  IACP  has  launched  a  new  Community-Police  Engagement  resource  page  featuring  a 
variety  of  tools  that  provide  policy  considerations  and  tangible  strategies  to  support  police  and  communities  in 
their  efforts  to  engage  in  productive  dialogue,  form  strong  partnerships,  and  identify  meaningful  solutions. 

Topics  include  community  policing;  bias  free  policing;  use  of  force;  leadership  and  culture;  and  recruitment  and 
promotional  testing.  At  a  time  when  agencies  are  looking  to  assess  their  policies  and  procedures  and  develop 
new  initiatives  to  maximize  community-police  engagement,  these  tools  provide  a  meaningful  base  to  help  public 
safety  stakeholders  develop  a  strong,  consistent  foundation. 
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Driver  Charged  With  Vehicular  Homicide  In  Death  Of  Seattle  Protester 

The  Washington  Post  (7/8,  Guarino)  reports,  "A  man  who  allegedly  struck  Black  Lives  Matter  protesters  in  Seattle  with  his 
car,  killing  one,  was  charged  with  reckless  driving,  vehicular  assault  and  vehicular  homicide  by  the  King  County  Prosecuting 
Attorney's  Office  on  Wednesday.  Washington  State  Patrol  and  the  FBI  are  investigating  the  case,  a  prominent  and  fatal  example 
of  recent  car  attacks  on  demonstrators."  The  Post  adds,  "When  protesters  gathered  for  a  Black  Femme  March  on  Interstate  5 
on  July  3,  it  was  the  19th  consecutive  night  activists  had  done  so,  according  to  the  state  patrol.  Near  midnight,  the  patrol  closed 
a  section  of  the  interstate  for  the  demonstration.  After  1  a.m.,  a  white  Jaguar,  seen  on  security  video  entering  the  highway 
through  an  off-ramp,  drove  through  the  group  at  high  speed,  authorities  said.  The  car  struck  two  people  -  Summer  Taylor,  a  24- 
year-old  Seattle  resident,  and  Diaz  Love,  32  -  then  fled  the  scene,  speeding  down  the  highway." 

The  New  York  Times  (7/8,  Waller,  Paybarah)  reports  that  Dawit  Kelete,  27,  "is  being  held  with  bail  set  at  $1.2  million 
and  is  expected  to  remain  in  jail,  the  King  County  Prosecuting  Attorney's  Office  said.  Two  of  the  charges,  vehicular  homicide  and 
vehicular  assault,  are  felonies,  a  spokesman  for  the  prosecuting  attorney's  office  said.  Mr.  Kelete  could  face  more  than  13  years 
in  prison,  said  the  spokesman,  Casey  McNerthney."  The  Times  adds,  "The  Washington  State  Patrol  and  the  F.B.I.  were  still 
investigating  the  matter,  and  Mr.  Kelete  could  face  additional  charges,  according  to  a  statement  from  the  prosecutor's  office." 

Crews  Of  ATM  Thieves  Using  Trucks  As  Battering  Rams  Inside  Baltimore,  Maryland  Businesses 

The  Baltimore  Sun  (7/8,  Fenton)  reports,  "Sometimes,  they  operate  with  the  speed  and  precision  of  a  NASCAR  pit  crew  - 
prying  open  the  locked  steel  gates  and  doors  of  small  businesses  around  Baltimore,  then  lifting  away  ATMs  and  hurrying  them 
to  a  waiting  pickup  truck  or  van.  Other  times,  the  thieves  use  vehicles  -  typically  stolen  -  as  battering  rams  to  force  entry.  They 
crash  through  storefronts  to  commit  a  small  bank  robbery  that  does  not  require  holding  up  a  teller."  The  Sun  adds,  "The  chaotic 
crimes  have  continued  on  and  off  for  months,  with  small  businesses  and  one  ATM  distributor  saying  it's  a  new  and  alarming 
trend.  During  the  course  of  one  hour  as  the  sun  came  up  June  27,  three  stores  were  hit  in  west,  northeast  and  midtown 
Baltimore,  including  someone  ramming  into  a  gas  station  on  Moravia  Road.  They've  used  different  methods  and  vehicles, 
causing  police  to  believe  it's  not  just  the  work  of  one  crew  and  that  others  are  getting  in  on  the  crime." 

Mexican  Drug  Cartel  Attacks  Public  Officials 

The  Wall  Street  Journal  (7/8,  Montes,  de  Cordoba,  Subscription  Publication)  reports  on  the  Jalisco  New  Generation  Cartel, 
saying  that  it  is  the  most  important  cartel  in  Mexico  and  has  mounted  direct  assaults  on  Mexican  officials  and  law  enforcement. 
According  to  the  Journal,  the  group  is  responsible  for  the  deaths  of  over  100  officials.  The  US  Drug  Enforcement  Administration 
is  offering  $10  million  for  information  leading  to  the  arrest  of  the  group's  leader  Nemesio  Oseguera. 
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POLICING  &  POLICY 


Minnesota  US  Attorney  Announces  Task  Force  To  Curb 
Gun  Violence 

The  Minneapolis  StarTribune  (7/8)  reports,  "U.S.  Attorney  Erica 
MacDonald  is  mobilizing  a  multiagency  command  center  for  a  new  task 
Force  aimed  at  curbing  "an  extraordinary  spike"  in  violence  in  the  Twin 
□ties  that  has  been  on  the  rise  since  Memorial  Day."  MacDonald  on 
Wednesday  "outlined  a  30-day  operation  that  will  deploy  state  and 
Federal  law  enforcement  across  a  dozen  agencies  in  response  to  a  spike 
n  gun  violence  and  other  crimes." 

The  St.  Paul  (MN)  Pioneer  Press  (7/8,  Harville)  reports,  "The 
Twin  Cities  Violent  Crime  Task  Force  will  work  with  additional  state  and 
Federal  resources  to  help  local  law  enforcement  investigate,  arrest  and 
prosecute  individuals  contributing  to  the  gun  violence  in  Minneapolis 
and  St.  Paul.  As  of  Tuesday  this  year,  101  people  have  been  shot  in  St.  Paul,  including  some  fatally,  according  to  police.  That's 
compared  with  70  as  of  the  end  of  June  2019.  'Law  enforcement  partners  will  utilize  the  task  force  to  maximize  intelligence 
gathering  and  information  sharing  capabilities  to  ensure  swift  and  precise  identification  of  those  individuals  who  are 
perpetrating  violence,'  the  U.S.  Attorney's  office  said  in  a  statement.  MacDonald  stressed  that  the  goal  of  the  task  force  is  'not 
to  flood  our  communities  with  law  enforcement,'  but  rather  to  create  a  way  for  community  members  and  city  leaders  to 
collaborate  with  law  enforcement  while  putting  a  stop  to  gun  violence." 


US  Launches  Anti-Crime  Initiative  In  Kansas  City,  Missouri 


The  Washington  Times  (7/8,  Boyer)  reports  the  Administration  is  "surging  federal  law-enforcement  agents  into  Kansas 
City,  Missouri,  to  fight  a  wave  of  violent  crime,  the  White  House  said  Wednesday."  Attorney  General  Barr  is  "launching  the 
operation  within  the  next  10  days  with  FBI  agents,  U.S.  marshals,  Drug  Enforcement  Administration  agents  and  officials  from 
the  Bureau  of  Alcohol,  Tobacco,  Firearms  and  Explosives  to  help  suppress  what  the  White  House  called  a  'tragic'  rise  in 
violence." 

KCTV-TV  Kansas  City,  MO  (7/8,  Smith)  reports  that  "Operation:  Legend"  is  "being  touted  by  the  Department  of  Justice 
as  a  response  to  the  surge  in  violent  crime  in  Kansas  City.  The  focus  of  the  new  initiative  is  to  increase  the  federal  law 
enforcement  present  in  the  city.  Press  Secretary  Kayleigh  McEnany  said  the  new  plan  was  inspired  by  Mayor  Quinton  Lucas' 
letter  to  Missouri  Governor  Mike  Parson  where  Lucas  wrote  that  Kansas  City  was  'at  a  crisis  point.'  The  letter,  originally  sent 
July  3,  was  looking  for  Parson  to  convene  a  special  session  of  the  Missouri  legislature  focused  on  growing  crime  in  Missouri 
cities." 

US  Sen.  Tim  Scott  Says  Police  Reform  Bill  Is  Not  Dead 

The  Washington  Times  (7/8,  Mordock)  reports  Sen.  Tim  Scott  (R-SC)  said  Wednesday  a  bill  he  authored  on  police  reform 
"is  not  dead  and  he  expects  an  agreement  with  the  Democrat-controlled  House  in  the  next  few  weeks."  Speaking  with  reporters 
at  a  press  event  with  Attorney  General  Barr,  "Scott  said  he  has  talked  with  House  Democrats  about  reaching  a  deal."  Said  the 
senator,  "Folks  are  now  calling  me  about  the  legislation  from  the  other  side,  suggesting  perhaps  it  is  not  dead.  We  may  have  a 
Lazarus  moment." 

New  Mexico  Mandates  Police  Body  Cameras 

The  AP  (7/8)  reports,  "New  Mexico  will  require  that  all  state  and  local  police  officers  wear  body  cameras  in  response  to 
concern  about  excessive  use  of  force  by  law  enforcement,  under  a  bill  signed  Wednesday  by  Gov.  Michelle  Lujan  Grisham."  The 
AP  adds,  "The  reforms  apply  to  local  and  state  law  enforcement  officers  with  the  exception  of  tribal  governments.  Law 
enforcement  agencies  must  archive  body  camera  footage  for  at  least  120  days."  The  state  legislature  "approved  the  policing 
reforms  during  a  four-day  special  session  in  June."  The  AP  adds,  "Police  agencies  that  flout  the  new  body-camera  requirement 
can  sued  for  withholding  evidence." 

Colorado  City  Passes  Resolution  Shielding  Officers  From  Portion  Of  State  Reform  Law 

The  Denver  Post  (7/8,  Aguilar)  reports,  "Just  weeks  after  Colorado  passed  a  sweeping  police  reform  law,  Greenwood 
Village  has  approved  a  measure  that  ensures  its  officers  aren't  on  the  hook  financially  if  they  mistreat  or  harm  a  citizen." 
Greenwood  Village  council  members  "unanimously  passed  a  resolution  Monday  saying  the  city  will  never  find  its  officers  have 
acted  in  bad  faith,"  and  "that  effectively  shields  them  from  having  to  face  personal  financial  liability  for  misconduct  on  the  job  - 
contrary  to  a  key  stipulation  of  Senate  Bill  217,  which  became  law  last  month.  'The  intent  of  Council's  resolution  was  simply  to 
inform  its  officers  that  as  their  employer,  they  would  not  make  such  a  (bad-faith)  finding  no  matter  what,'  Greenwood  Village 
city  attorney  Tonya  Haas  Davidson  wrote  in  an  email  Wednesday.  'Nowhere  in  the  law  is  an  employer  ever  required  to  make  a 
finding  of  bad  faith.'" 

Chicago  Police  Announce  Formation  Of  Citywide  Unit  To  Fight  Violent  Crime 

The  Chicago  Sun-Times  (7/8)  reports,  "Chicago  police  announced  Tuesday  it  will  create  a  citywide  violent  crime  unit  after 
three  consecutive  weekends  with  at  least  65  people  shot  and  multiple  children  killed.  The  specialized  unit  is  meant  'to  tackle 
violent  crime  and  create  community  partnerships  in  some  of  our  most  challenging  areas,'  the  department  said.  'The  ultimate 
goal  of  the  Chicago  Police  Department's  organizational  restructuring  that  began  earlier  this  year  has  always  been  to  bolster 
police  resources  under  the  authority  of  district  commanders,  while  also  being  able  to  address  spikes  in  violent  crime  citywide,' 
the  department  said."  The  Sun-Times  adds,  "Once  implemented,  the  new  unit  will  'impact'  gun,  saturation  and  gang 
enforcement  teams  in  each  of  the  city's  five  police  Areas,  the  department  said.  In  the  meantime,  police  are  bolstering  the 
Summer  Mobile  Patrol  Unit,  a  task  force  of  100  officers  focusing  on  high-crime  areas." 


After  George  Floyd's  death  and  the  response  that  followed,  police  leaders,  community  members,  and  elected 
officials  in  the  United  States  and  around  the  world  are  looking  for  collaborative,  constructive  ways  to  move  public 
safety  efforts  forward.  The  IACP  has  launched  a  new  Community-Police  Engagement  resource  page  featuring  a 
variety  of  tools  that  provide  policy  considerations  and  tangible  strategies  to  support  police  and  communities  in 
their  efforts  to  engage  in  productive  dialogue,  form  strong  partnerships,  and  identify  meaningful  solutions. 

Topics  include  community  policing;  bias  free  policing;  use  of  force;  leadership  and  culture;  and  recruitment  and 
promotional  testing.  At  a  time  when  agencies  are  looking  to  assess  their  policies  and  procedures  and  develop 
new  initiatives  to  maximize  community-police  engagement,  these  tools  provide  a  meaningful  base  to  help  public 
safety  stakeholders  develop  a  strong,  consistent  foundation. 
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CRIME  &  DRUGS 


Driver  Charged  With  Vehicular  Homicide  In  Death  Of  Seattle  Protester 

The  Washington  Post  (7/8,  Guarino)  reports,  "A  man  who  allegedly  struck  Black  Lives  Matter  protesters  in  Seattle  with  his 
car,  killing  one,  was  charged  with  reckless  driving,  vehicular  assault  and  vehicular  homicide  by  the  King  County  Prosecuting 
Attorney's  Office  on  Wednesday.  Washington  State  Patrol  and  the  FBI  are  investigating  the  case,  a  prominent  and  fatal  example 
of  recent  car  attacks  on  demonstrators."  The  Post  adds,  "When  protesters  gathered  for  a  Black  Femme  March  on  Interstate  5 
on  July  3,  it  was  the  19th  consecutive  night  activists  had  done  so,  according  to  the  state  patrol.  Near  midnight,  the  patrol  closed 
a  section  of  the  interstate  for  the  demonstration.  After  1  a.m.,  a  white  Jaguar,  seen  on  security  video  entering  the  highway 
through  an  off-ramp,  drove  through  the  group  at  high  speed,  authorities  said.  The  car  struck  two  people  -  Summer  Taylor,  a  24- 
year-old  Seattle  resident,  and  Diaz  Love,  32  -  then  fled  the  scene,  speeding  down  the  highway." 

The  New  York  Times  (7/8,  Waller,  Paybarah)  reports  that  Dawit  Kelete,  27,  "is  being  held  with  bail  set  at  $1.2  million 
and  is  expected  to  remain  in  jail,  the  King  County  Prosecuting  Attorney's  Office  said.  Two  of  the  charges,  vehicular  homicide  and 
vehicular  assault,  are  felonies,  a  spokesman  for  the  prosecuting  attorney's  office  said.  Mr.  Kelete  could  face  more  than  13  years 
in  prison,  said  the  spokesman,  Casey  McNerthney."  The  Times  adds,  "The  Washington  State  Patrol  and  the  F.B.I.  were  still 
investigating  the  matter,  and  Mr.  Kelete  could  face  additional  charges,  according  to  a  statement  from  the  prosecutor's  office." 

Crews  Of  ATM  Thieves  Using  Trucks  As  Battering  Rams  Inside  Baltimore,  Maryland  Businesses 

The  Baltimore  Sun  (7/8,  Fenton)  reports,  "Sometimes,  they  operate  with  the  speed  and  precision  of  a  NASCAR  pit  crew  - 
prying  open  the  locked  steel  gates  and  doors  of  small  businesses  around  Baltimore,  then  lifting  away  ATMs  and  hurrying  them 
to  a  waiting  pickup  truck  or  van.  Other  times,  the  thieves  use  vehicles  -  typically  stolen  -  as  battering  rams  to  force  entry.  They 
crash  through  storefronts  to  commit  a  small  bank  robbery  that  does  not  require  holding  up  a  teller."  The  Sun  adds,  "The  chaotic 
crimes  have  continued  on  and  off  for  months,  with  small  businesses  and  one  ATM  distributor  saying  it's  a  new  and  alarming 
trend.  During  the  course  of  one  hour  as  the  sun  came  up  June  27,  three  stores  were  hit  in  west,  northeast  and  midtown 
Baltimore,  including  someone  ramming  into  a  gas  station  on  Moravia  Road.  They've  used  different  methods  and  vehicles, 
causing  police  to  believe  it's  not  just  the  work  of  one  crew  and  that  others  are  getting  in  on  the  crime." 

Mexican  Drug  Cartel  Attacks  Public  Officials 

The  Wall  Street  Journal  (7/8,  Montes,  de  Cordoba,  Subscription  Publication)  reports  on  the  Jalisco  New  Generation  Cartel, 
saying  that  it  is  the  most  important  cartel  in  Mexico  and  has  mounted  direct  assaults  on  Mexican  officials  and  law  enforcement. 
According  to  the  Journal,  the  group  is  responsible  for  the  deaths  of  over  100  officials.  The  US  Drug  Enforcement  Administration 
is  offering  $10  million  for  information  leading  to  the  arrest  of  the  group's  leader  Nemesio  Oseguera. 
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POLICING  &  POLICY 


Minnesota  US  Attorney  Announces  Task  Force  To  Curb 
Gun  Violence 

The  Minneapolis  StarTribune  (7/8)  reports,  "U.S.  Attorney  Erica 
MacDonald  is  mobilizing  a  multiagency  command  center  for  a  new  task 
Force  aimed  at  curbing  "an  extraordinary  spike"  in  violence  in  the  Twin 
□ties  that  has  been  on  the  rise  since  Memorial  Day."  MacDonald  on 
Wednesday  "outlined  a  30-day  operation  that  will  deploy  state  and 
Federal  law  enforcement  across  a  dozen  agencies  in  response  to  a  spike 
n  gun  violence  and  other  crimes." 

The  St.  Paul  (MN)  Pioneer  Press  (7/8,  Harville)  reports,  "The 
Twin  Cities  Violent  Crime  Task  Force  will  work  with  additional  state  and 
Federal  resources  to  help  local  law  enforcement  investigate,  arrest  and 
prosecute  individuals  contributing  to  the  gun  violence  in  Minneapolis 
and  St.  Paul.  As  of  Tuesday  this  year,  101  people  have  been  shot  in  St.  Paul,  including  some  fatally,  according  to  police.  That's 
compared  with  70  as  of  the  end  of  June  2019.  'Law  enforcement  partners  will  utilize  the  task  force  to  maximize  intelligence 
gathering  and  information  sharing  capabilities  to  ensure  swift  and  precise  identification  of  those  individuals  who  are 
perpetrating  violence,'  the  U.S.  Attorney's  office  said  in  a  statement.  MacDonald  stressed  that  the  goal  of  the  task  force  is  'not 
to  flood  our  communities  with  law  enforcement,'  but  rather  to  create  a  way  for  community  members  and  city  leaders  to 
collaborate  with  law  enforcement  while  putting  a  stop  to  gun  violence." 


US  Launches  Anti-Crime  Initiative  In  Kansas  City,  Missouri 


The  Washington  Times  (7/8,  Boyer)  reports  the  Administration  is  "surging  federal  law-enforcement  agents  into  Kansas 
City,  Missouri,  to  fight  a  wave  of  violent  crime,  the  White  House  said  Wednesday."  Attorney  General  Barr  is  "launching  the 
operation  within  the  next  10  days  with  FBI  agents,  U.S.  marshals,  Drug  Enforcement  Administration  agents  and  officials  from 
the  Bureau  of  Alcohol,  Tobacco,  Firearms  and  Explosives  to  help  suppress  what  the  White  House  called  a  'tragic'  rise  in 
violence." 

KCTV-TV  Kansas  City,  MO  (7/8,  Smith)  reports  that  "Operation:  Legend"  is  "being  touted  by  the  Department  of  Justice 
as  a  response  to  the  surge  in  violent  crime  in  Kansas  City.  The  focus  of  the  new  initiative  is  to  increase  the  federal  law 
enforcement  present  in  the  city.  Press  Secretary  Kayleigh  McEnany  said  the  new  plan  was  inspired  by  Mayor  Quinton  Lucas' 
letter  to  Missouri  Governor  Mike  Parson  where  Lucas  wrote  that  Kansas  City  was  'at  a  crisis  point.'  The  letter,  originally  sent 
July  3,  was  looking  for  Parson  to  convene  a  special  session  of  the  Missouri  legislature  focused  on  growing  crime  in  Missouri 
cities." 

US  Sen.  Tim  Scott  Says  Police  Reform  Bill  Is  Not  Dead 

The  Washington  Times  (7/8,  Mordock)  reports  Sen.  Tim  Scott  (R-SC)  said  Wednesday  a  bill  he  authored  on  police  reform 
"is  not  dead  and  he  expects  an  agreement  with  the  Democrat-controlled  House  in  the  next  few  weeks."  Speaking  with  reporters 
at  a  press  event  with  Attorney  General  Barr,  "Scott  said  he  has  talked  with  House  Democrats  about  reaching  a  deal."  Said  the 
senator,  "Folks  are  now  calling  me  about  the  legislation  from  the  other  side,  suggesting  perhaps  it  is  not  dead.  We  may  have  a 
Lazarus  moment." 

New  Mexico  Mandates  Police  Body  Cameras 

The  AP  (7/8)  reports,  "New  Mexico  will  require  that  all  state  and  local  police  officers  wear  body  cameras  in  response  to 
concern  about  excessive  use  of  force  by  law  enforcement,  under  a  bill  signed  Wednesday  by  Gov.  Michelle  Lujan  Grisham."  The 
AP  adds,  "The  reforms  apply  to  local  and  state  law  enforcement  officers  with  the  exception  of  tribal  governments.  Law 
enforcement  agencies  must  archive  body  camera  footage  for  at  least  120  days."  The  state  legislature  "approved  the  policing 
reforms  during  a  four-day  special  session  in  June."  The  AP  adds,  "Police  agencies  that  flout  the  new  body-camera  requirement 
can  sued  for  withholding  evidence." 

Colorado  City  Passes  Resolution  Shielding  Officers  From  Portion  Of  State  Reform  Law 

The  Denver  Post  (7/8,  Aguilar)  reports,  "Just  weeks  after  Colorado  passed  a  sweeping  police  reform  law,  Greenwood 
Village  has  approved  a  measure  that  ensures  its  officers  aren't  on  the  hook  financially  if  they  mistreat  or  harm  a  citizen." 
Greenwood  Village  council  members  "unanimously  passed  a  resolution  Monday  saying  the  city  will  never  find  its  officers  have 
acted  in  bad  faith,"  and  "that  effectively  shields  them  from  having  to  face  personal  financial  liability  for  misconduct  on  the  job  - 
contrary  to  a  key  stipulation  of  Senate  Bill  217,  which  became  law  last  month.  'The  intent  of  Council's  resolution  was  simply  to 
inform  its  officers  that  as  their  employer,  they  would  not  make  such  a  (bad-faith)  finding  no  matter  what,'  Greenwood  Village 
city  attorney  Tonya  Haas  Davidson  wrote  in  an  email  Wednesday.  'Nowhere  in  the  law  is  an  employer  ever  required  to  make  a 
finding  of  bad  faith.'" 

Chicago  Police  Announce  Formation  Of  Citywide  Unit  To  Fight  Violent  Crime 

The  Chicago  Sun-Times  (7/8)  reports,  "Chicago  police  announced  Tuesday  it  will  create  a  citywide  violent  crime  unit  after 
three  consecutive  weekends  with  at  least  65  people  shot  and  multiple  children  killed.  The  specialized  unit  is  meant  'to  tackle 
violent  crime  and  create  community  partnerships  in  some  of  our  most  challenging  areas,'  the  department  said.  'The  ultimate 
goal  of  the  Chicago  Police  Department's  organizational  restructuring  that  began  earlier  this  year  has  always  been  to  bolster 
police  resources  under  the  authority  of  district  commanders,  while  also  being  able  to  address  spikes  in  violent  crime  citywide,' 
the  department  said."  The  Sun-Times  adds,  "Once  implemented,  the  new  unit  will  'impact'  gun,  saturation  and  gang 
enforcement  teams  in  each  of  the  city's  five  police  Areas,  the  department  said.  In  the  meantime,  police  are  bolstering  the 
Summer  Mobile  Patrol  Unit,  a  task  force  of  100  officers  focusing  on  high-crime  areas." 


After  George  Floyd's  death  and  the  response  that  followed,  police  leaders,  community  members,  and  elected 
officials  in  the  United  States  and  around  the  world  are  looking  for  collaborative,  constructive  ways  to  move  public 
safety  efforts  forward.  The  IACP  has  launched  a  new  Community-Police  Engagement  resource  page  featuring  a 
variety  of  tools  that  provide  policy  considerations  and  tangible  strategies  to  support  police  and  communities  in 
their  efforts  to  engage  in  productive  dialogue,  form  strong  partnerships,  and  identify  meaningful  solutions. 

Topics  include  community  policing;  bias  free  policing;  use  of  force;  leadership  and  culture;  and  recruitment  and 
promotional  testing.  At  a  time  when  agencies  are  looking  to  assess  their  policies  and  procedures  and  develop 
new  initiatives  to  maximize  community-police  engagement,  these  tools  provide  a  meaningful  base  to  help  public 
safety  stakeholders  develop  a  strong,  consistent  foundation. 
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CRIME  &  DRUGS 


Driver  Charged  With  Vehicular  Homicide  In  Death  Of  Seattle  Protester 

The  Washington  Post  (7/8,  Guarino)  reports,  "A  man  who  allegedly  struck  Black  Lives  Matter  protesters  in  Seattle  with  his 
car,  killing  one,  was  charged  with  reckless  driving,  vehicular  assault  and  vehicular  homicide  by  the  King  County  Prosecuting 
Attorney's  Office  on  Wednesday.  Washington  State  Patrol  and  the  FBI  are  investigating  the  case,  a  prominent  and  fatal  example 
of  recent  car  attacks  on  demonstrators."  The  Post  adds,  "When  protesters  gathered  for  a  Black  Femme  March  on  Interstate  5 
on  July  3,  it  was  the  19th  consecutive  night  activists  had  done  so,  according  to  the  state  patrol.  Near  midnight,  the  patrol  closed 
a  section  of  the  interstate  for  the  demonstration.  After  1  a.m.,  a  white  Jaguar,  seen  on  security  video  entering  the  highway 
through  an  off-ramp,  drove  through  the  group  at  high  speed,  authorities  said.  The  car  struck  two  people  -  Summer  Taylor,  a  24- 
year-old  Seattle  resident,  and  Diaz  Love,  32  -  then  fled  the  scene,  speeding  down  the  highway." 

The  New  York  Times  (7/8,  Waller,  Paybarah)  reports  that  Dawit  Kelete,  27,  "is  being  held  with  bail  set  at  $1.2  million 
and  is  expected  to  remain  in  jail,  the  King  County  Prosecuting  Attorney's  Office  said.  Two  of  the  charges,  vehicular  homicide  and 
vehicular  assault,  are  felonies,  a  spokesman  for  the  prosecuting  attorney's  office  said.  Mr.  Kelete  could  face  more  than  13  years 
in  prison,  said  the  spokesman,  Casey  McNerthney."  The  Times  adds,  "The  Washington  State  Patrol  and  the  F.B.I.  were  still 
investigating  the  matter,  and  Mr.  Kelete  could  face  additional  charges,  according  to  a  statement  from  the  prosecutor's  office." 

Crews  Of  ATM  Thieves  Using  Trucks  As  Battering  Rams  Inside  Baltimore,  Maryland  Businesses 

The  Baltimore  Sun  (7/8,  Fenton)  reports,  "Sometimes,  they  operate  with  the  speed  and  precision  of  a  NASCAR  pit  crew  - 
prying  open  the  locked  steel  gates  and  doors  of  small  businesses  around  Baltimore,  then  lifting  away  ATMs  and  hurrying  them 
to  a  waiting  pickup  truck  or  van.  Other  times,  the  thieves  use  vehicles  -  typically  stolen  -  as  battering  rams  to  force  entry.  They 
crash  through  storefronts  to  commit  a  small  bank  robbery  that  does  not  require  holding  up  a  teller."  The  Sun  adds,  "The  chaotic 
crimes  have  continued  on  and  off  for  months,  with  small  businesses  and  one  ATM  distributor  saying  it's  a  new  and  alarming 
trend.  During  the  course  of  one  hour  as  the  sun  came  up  June  27,  three  stores  were  hit  in  west,  northeast  and  midtown 
Baltimore,  including  someone  ramming  into  a  gas  station  on  Moravia  Road.  They've  used  different  methods  and  vehicles, 
causing  police  to  believe  it's  not  just  the  work  of  one  crew  and  that  others  are  getting  in  on  the  crime." 

Mexican  Drug  Cartel  Attacks  Public  Officials 

The  Wall  Street  Journal  (7/8,  Montes,  de  Cordoba,  Subscription  Publication)  reports  on  the  Jalisco  New  Generation  Cartel, 
saying  that  it  is  the  most  important  cartel  in  Mexico  and  has  mounted  direct  assaults  on  Mexican  officials  and  law  enforcement. 
According  to  the  Journal,  the  group  is  responsible  for  the  deaths  of  over  100  officials.  The  US  Drug  Enforcement  Administration 
is  offering  $10  million  for  information  leading  to  the  arrest  of  the  group's  leader  Nemesio  Oseguera. 
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Minnesota  US  Attorney  Announces  Task  Force  To  Curb 
Gun  Violence 

The  Minneapolis  StarTribune  (7/8)  reports,  "U.S.  Attorney  Erica 
MacDonald  is  mobilizing  a  multiagency  command  center  for  a  new  task 
Force  aimed  at  curbing  "an  extraordinary  spike"  in  violence  in  the  Twin 
□ties  that  has  been  on  the  rise  since  Memorial  Day."  MacDonald  on 
Wednesday  "outlined  a  30-day  operation  that  will  deploy  state  and 
Federal  law  enforcement  across  a  dozen  agencies  in  response  to  a  spike 
n  gun  violence  and  other  crimes." 

The  St.  Paul  (MN)  Pioneer  Press  (7/8,  Harville)  reports,  "The 
Twin  Cities  Violent  Crime  Task  Force  will  work  with  additional  state  and 
Federal  resources  to  help  local  law  enforcement  investigate,  arrest  and 
prosecute  individuals  contributing  to  the  gun  violence  in  Minneapolis 
and  St.  Paul.  As  of  Tuesday  this  year,  101  people  have  been  shot  in  St.  Paul,  including  some  fatally,  according  to  police.  That's 
compared  with  70  as  of  the  end  of  June  2019.  'Law  enforcement  partners  will  utilize  the  task  force  to  maximize  intelligence 
gathering  and  information  sharing  capabilities  to  ensure  swift  and  precise  identification  of  those  individuals  who  are 
perpetrating  violence,'  the  U.S.  Attorney's  office  said  in  a  statement.  MacDonald  stressed  that  the  goal  of  the  task  force  is  'not 
to  flood  our  communities  with  law  enforcement,'  but  rather  to  create  a  way  for  community  members  and  city  leaders  to 
collaborate  with  law  enforcement  while  putting  a  stop  to  gun  violence." 


US  Launches  Anti-Crime  Initiative  In  Kansas  City,  Missouri 


The  Washington  Times  (7/8,  Boyer)  reports  the  Administration  is  "surging  federal  law-enforcement  agents  into  Kansas 
City,  Missouri,  to  fight  a  wave  of  violent  crime,  the  White  House  said  Wednesday."  Attorney  General  Barr  is  "launching  the 
operation  within  the  next  10  days  with  FBI  agents,  U.S.  marshals,  Drug  Enforcement  Administration  agents  and  officials  from 
the  Bureau  of  Alcohol,  Tobacco,  Firearms  and  Explosives  to  help  suppress  what  the  White  House  called  a  'tragic'  rise  in 
violence." 

KCTV-TV  Kansas  City,  MO  (7/8,  Smith)  reports  that  "Operation:  Legend"  is  "being  touted  by  the  Department  of  Justice 
as  a  response  to  the  surge  in  violent  crime  in  Kansas  City.  The  focus  of  the  new  initiative  is  to  increase  the  federal  law 
enforcement  present  in  the  city.  Press  Secretary  Kayleigh  McEnany  said  the  new  plan  was  inspired  by  Mayor  Quinton  Lucas' 
letter  to  Missouri  Governor  Mike  Parson  where  Lucas  wrote  that  Kansas  City  was  'at  a  crisis  point.'  The  letter,  originally  sent 
July  3,  was  looking  for  Parson  to  convene  a  special  session  of  the  Missouri  legislature  focused  on  growing  crime  in  Missouri 
cities." 

US  Sen.  Tim  Scott  Says  Police  Reform  Bill  Is  Not  Dead 

The  Washington  Times  (7/8,  Mordock)  reports  Sen.  Tim  Scott  (R-SC)  said  Wednesday  a  bill  he  authored  on  police  reform 
"is  not  dead  and  he  expects  an  agreement  with  the  Democrat-controlled  House  in  the  next  few  weeks."  Speaking  with  reporters 
at  a  press  event  with  Attorney  General  Barr,  "Scott  said  he  has  talked  with  House  Democrats  about  reaching  a  deal."  Said  the 
senator,  "Folks  are  now  calling  me  about  the  legislation  from  the  other  side,  suggesting  perhaps  it  is  not  dead.  We  may  have  a 
Lazarus  moment." 

New  Mexico  Mandates  Police  Body  Cameras 

The  AP  (7/8)  reports,  "New  Mexico  will  require  that  all  state  and  local  police  officers  wear  body  cameras  in  response  to 
concern  about  excessive  use  of  force  by  law  enforcement,  under  a  bill  signed  Wednesday  by  Gov.  Michelle  Lujan  Grisham."  The 
AP  adds,  "The  reforms  apply  to  local  and  state  law  enforcement  officers  with  the  exception  of  tribal  governments.  Law 
enforcement  agencies  must  archive  body  camera  footage  for  at  least  120  days."  The  state  legislature  "approved  the  policing 
reforms  during  a  four-day  special  session  in  June."  The  AP  adds,  "Police  agencies  that  flout  the  new  body-camera  requirement 
can  sued  for  withholding  evidence." 

Colorado  City  Passes  Resolution  Shielding  Officers  From  Portion  Of  State  Reform  Law 

The  Denver  Post  (7/8,  Aguilar)  reports,  "Just  weeks  after  Colorado  passed  a  sweeping  police  reform  law,  Greenwood 
Village  has  approved  a  measure  that  ensures  its  officers  aren't  on  the  hook  financially  if  they  mistreat  or  harm  a  citizen." 
Greenwood  Village  council  members  "unanimously  passed  a  resolution  Monday  saying  the  city  will  never  find  its  officers  have 
acted  in  bad  faith,"  and  "that  effectively  shields  them  from  having  to  face  personal  financial  liability  for  misconduct  on  the  job  - 
contrary  to  a  key  stipulation  of  Senate  Bill  217,  which  became  law  last  month.  'The  intent  of  Council's  resolution  was  simply  to 
inform  its  officers  that  as  their  employer,  they  would  not  make  such  a  (bad-faith)  finding  no  matter  what,'  Greenwood  Village 
city  attorney  Tonya  Haas  Davidson  wrote  in  an  email  Wednesday.  'Nowhere  in  the  law  is  an  employer  ever  required  to  make  a 
finding  of  bad  faith.'" 

Chicago  Police  Announce  Formation  Of  Citywide  Unit  To  Fight  Violent  Crime 

The  Chicago  Sun-Times  (7/8)  reports,  "Chicago  police  announced  Tuesday  it  will  create  a  citywide  violent  crime  unit  after 
three  consecutive  weekends  with  at  least  65  people  shot  and  multiple  children  killed.  The  specialized  unit  is  meant  'to  tackle 
violent  crime  and  create  community  partnerships  in  some  of  our  most  challenging  areas,'  the  department  said.  'The  ultimate 
goal  of  the  Chicago  Police  Department's  organizational  restructuring  that  began  earlier  this  year  has  always  been  to  bolster 
police  resources  under  the  authority  of  district  commanders,  while  also  being  able  to  address  spikes  in  violent  crime  citywide,' 
the  department  said."  The  Sun-Times  adds,  "Once  implemented,  the  new  unit  will  'impact'  gun,  saturation  and  gang 
enforcement  teams  in  each  of  the  city's  five  police  Areas,  the  department  said.  In  the  meantime,  police  are  bolstering  the 
Summer  Mobile  Patrol  Unit,  a  task  force  of  100  officers  focusing  on  high-crime  areas." 


After  George  Floyd's  death  and  the  response  that  followed,  police  leaders,  community  members,  and  elected 
officials  in  the  United  States  and  around  the  world  are  looking  for  collaborative,  constructive  ways  to  move  public 
safety  efforts  forward.  The  IACP  has  launched  a  new  Community-Police  Engagement  resource  page  featuring  a 
variety  of  tools  that  provide  policy  considerations  and  tangible  strategies  to  support  police  and  communities  in 
their  efforts  to  engage  in  productive  dialogue,  form  strong  partnerships,  and  identify  meaningful  solutions. 

Topics  include  community  policing;  bias  free  policing;  use  of  force;  leadership  and  culture;  and  recruitment  and 
promotional  testing.  At  a  time  when  agencies  are  looking  to  assess  their  policies  and  procedures  and  develop 
new  initiatives  to  maximize  community-police  engagement,  these  tools  provide  a  meaningful  base  to  help  public 
safety  stakeholders  develop  a  strong,  consistent  foundation. 
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Driver  Charged  With  Vehicular  Homicide  In  Death  Of  Seattle  Protester 

The  Washington  Post  (7/8,  Guarino)  reports,  "A  man  who  allegedly  struck  Black  Lives  Matter  protesters  in  Seattle  with  his 
car,  killing  one,  was  charged  with  reckless  driving,  vehicular  assault  and  vehicular  homicide  by  the  King  County  Prosecuting 
Attorney's  Office  on  Wednesday.  Washington  State  Patrol  and  the  FBI  are  investigating  the  case,  a  prominent  and  fatal  example 
of  recent  car  attacks  on  demonstrators."  The  Post  adds,  "When  protesters  gathered  for  a  Black  Femme  March  on  Interstate  5 
on  July  3,  it  was  the  19th  consecutive  night  activists  had  done  so,  according  to  the  state  patrol.  Near  midnight,  the  patrol  closed 
a  section  of  the  interstate  for  the  demonstration.  After  1  a.m.,  a  white  Jaguar,  seen  on  security  video  entering  the  highway 
through  an  off-ramp,  drove  through  the  group  at  high  speed,  authorities  said.  The  car  struck  two  people  -  Summer  Taylor,  a  24- 
year-old  Seattle  resident,  and  Diaz  Love,  32  -  then  fled  the  scene,  speeding  down  the  highway." 

The  New  York  Times  (7/8,  Waller,  Paybarah)  reports  that  Dawit  Kelete,  27,  "is  being  held  with  bail  set  at  $1.2  million 
and  is  expected  to  remain  in  jail,  the  King  County  Prosecuting  Attorney's  Office  said.  Two  of  the  charges,  vehicular  homicide  and 
vehicular  assault,  are  felonies,  a  spokesman  for  the  prosecuting  attorney's  office  said.  Mr.  Kelete  could  face  more  than  13  years 
in  prison,  said  the  spokesman,  Casey  McNerthney."  The  Times  adds,  "The  Washington  State  Patrol  and  the  F.B.I.  were  still 
investigating  the  matter,  and  Mr.  Kelete  could  face  additional  charges,  according  to  a  statement  from  the  prosecutor's  office." 

Crews  Of  ATM  Thieves  Using  Trucks  As  Battering  Rams  Inside  Baltimore,  Maryland  Businesses 

The  Baltimore  Sun  (7/8,  Fenton)  reports,  "Sometimes,  they  operate  with  the  speed  and  precision  of  a  NASCAR  pit  crew  - 
prying  open  the  locked  steel  gates  and  doors  of  small  businesses  around  Baltimore,  then  lifting  away  ATMs  and  hurrying  them 
to  a  waiting  pickup  truck  or  van.  Other  times,  the  thieves  use  vehicles  -  typically  stolen  -  as  battering  rams  to  force  entry.  They 
crash  through  storefronts  to  commit  a  small  bank  robbery  that  does  not  require  holding  up  a  teller."  The  Sun  adds,  "The  chaotic 
crimes  have  continued  on  and  off  for  months,  with  small  businesses  and  one  ATM  distributor  saying  it's  a  new  and  alarming 
trend.  During  the  course  of  one  hour  as  the  sun  came  up  June  27,  three  stores  were  hit  in  west,  northeast  and  midtown 
Baltimore,  including  someone  ramming  into  a  gas  station  on  Moravia  Road.  They've  used  different  methods  and  vehicles, 
causing  police  to  believe  it's  not  just  the  work  of  one  crew  and  that  others  are  getting  in  on  the  crime." 

Mexican  Drug  Cartel  Attacks  Public  Officials 

The  Wall  Street  Journal  (7/8,  Montes,  de  Cordoba,  Subscription  Publication)  reports  on  the  Jalisco  New  Generation  Cartel, 
saying  that  it  is  the  most  important  cartel  in  Mexico  and  has  mounted  direct  assaults  on  Mexican  officials  and  law  enforcement. 
According  to  the  Journal,  the  group  is  responsible  for  the  deaths  of  over  100  officials.  The  US  Drug  Enforcement  Administration 
is  offering  $10  million  for  information  leading  to  the  arrest  of  the  group's  leader  Nemesio  Oseguera. 
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POLICING  &  POLICY 


Minnesota  US  Attorney  Announces  Task  Force  To  Curb 
Gun  Violence 

The  Minneapolis  StarTribune  (7/8)  reports,  "U.S.  Attorney  Erica 
MacDonald  is  mobilizing  a  multiagency  command  center  for  a  new  task 
Force  aimed  at  curbing  "an  extraordinary  spike"  in  violence  in  the  Twin 
□ties  that  has  been  on  the  rise  since  Memorial  Day."  MacDonald  on 
Wednesday  "outlined  a  30-day  operation  that  will  deploy  state  and 
Federal  law  enforcement  across  a  dozen  agencies  in  response  to  a  spike 
n  gun  violence  and  other  crimes." 

The  St.  Paul  (MN)  Pioneer  Press  (7/8,  Harville)  reports,  "The 
Twin  Cities  Violent  Crime  Task  Force  will  work  with  additional  state  and 
Federal  resources  to  help  local  law  enforcement  investigate,  arrest  and 
prosecute  individuals  contributing  to  the  gun  violence  in  Minneapolis 
and  St.  Paul.  As  of  Tuesday  this  year,  101  people  have  been  shot  in  St.  Paul,  including  some  fatally,  according  to  police.  That's 
compared  with  70  as  of  the  end  of  June  2019.  'Law  enforcement  partners  will  utilize  the  task  force  to  maximize  intelligence 
gathering  and  information  sharing  capabilities  to  ensure  swift  and  precise  identification  of  those  individuals  who  are 
perpetrating  violence,'  the  U.S.  Attorney's  office  said  in  a  statement.  MacDonald  stressed  that  the  goal  of  the  task  force  is  'not 
to  flood  our  communities  with  law  enforcement,'  but  rather  to  create  a  way  for  community  members  and  city  leaders  to 
collaborate  with  law  enforcement  while  putting  a  stop  to  gun  violence." 


US  Launches  Anti-Crime  Initiative  In  Kansas  City,  Missouri 


The  Washington  Times  (7/8,  Boyer)  reports  the  Administration  is  "surging  federal  law-enforcement  agents  into  Kansas 
City,  Missouri,  to  fight  a  wave  of  violent  crime,  the  White  House  said  Wednesday."  Attorney  General  Barr  is  "launching  the 
operation  within  the  next  10  days  with  FBI  agents,  U.S.  marshals,  Drug  Enforcement  Administration  agents  and  officials  from 
the  Bureau  of  Alcohol,  Tobacco,  Firearms  and  Explosives  to  help  suppress  what  the  White  House  called  a  'tragic'  rise  in 
violence." 

KCTV-TV  Kansas  City,  MO  (7/8,  Smith)  reports  that  "Operation:  Legend"  is  "being  touted  by  the  Department  of  Justice 
as  a  response  to  the  surge  in  violent  crime  in  Kansas  City.  The  focus  of  the  new  initiative  is  to  increase  the  federal  law 
enforcement  present  in  the  city.  Press  Secretary  Kayleigh  McEnany  said  the  new  plan  was  inspired  by  Mayor  Quinton  Lucas' 
letter  to  Missouri  Governor  Mike  Parson  where  Lucas  wrote  that  Kansas  City  was  'at  a  crisis  point.'  The  letter,  originally  sent 
July  3,  was  looking  for  Parson  to  convene  a  special  session  of  the  Missouri  legislature  focused  on  growing  crime  in  Missouri 
cities." 

US  Sen.  Tim  Scott  Says  Police  Reform  Bill  Is  Not  Dead 

The  Washington  Times  (7/8,  Mordock)  reports  Sen.  Tim  Scott  (R-SC)  said  Wednesday  a  bill  he  authored  on  police  reform 
"is  not  dead  and  he  expects  an  agreement  with  the  Democrat-controlled  House  in  the  next  few  weeks."  Speaking  with  reporters 
at  a  press  event  with  Attorney  General  Barr,  "Scott  said  he  has  talked  with  House  Democrats  about  reaching  a  deal."  Said  the 
senator,  "Folks  are  now  calling  me  about  the  legislation  from  the  other  side,  suggesting  perhaps  it  is  not  dead.  We  may  have  a 
Lazarus  moment." 

New  Mexico  Mandates  Police  Body  Cameras 

The  AP  (7/8)  reports,  "New  Mexico  will  require  that  all  state  and  local  police  officers  wear  body  cameras  in  response  to 
concern  about  excessive  use  of  force  by  law  enforcement,  under  a  bill  signed  Wednesday  by  Gov.  Michelle  Lujan  Grisham."  The 
AP  adds,  "The  reforms  apply  to  local  and  state  law  enforcement  officers  with  the  exception  of  tribal  governments.  Law 
enforcement  agencies  must  archive  body  camera  footage  for  at  least  120  days."  The  state  legislature  "approved  the  policing 
reforms  during  a  four-day  special  session  in  June."  The  AP  adds,  "Police  agencies  that  flout  the  new  body-camera  requirement 
can  sued  for  withholding  evidence." 

Colorado  City  Passes  Resolution  Shielding  Officers  From  Portion  Of  State  Reform  Law 

The  Denver  Post  (7/8,  Aguilar)  reports,  "Just  weeks  after  Colorado  passed  a  sweeping  police  reform  law,  Greenwood 
Village  has  approved  a  measure  that  ensures  its  officers  aren't  on  the  hook  financially  if  they  mistreat  or  harm  a  citizen." 
Greenwood  Village  council  members  "unanimously  passed  a  resolution  Monday  saying  the  city  will  never  find  its  officers  have 
acted  in  bad  faith,"  and  "that  effectively  shields  them  from  having  to  face  personal  financial  liability  for  misconduct  on  the  job  - 
contrary  to  a  key  stipulation  of  Senate  Bill  217,  which  became  law  last  month.  'The  intent  of  Council's  resolution  was  simply  to 
inform  its  officers  that  as  their  employer,  they  would  not  make  such  a  (bad-faith)  finding  no  matter  what,'  Greenwood  Village 
city  attorney  Tonya  Haas  Davidson  wrote  in  an  email  Wednesday.  'Nowhere  in  the  law  is  an  employer  ever  required  to  make  a 
finding  of  bad  faith.'" 

Chicago  Police  Announce  Formation  Of  Citywide  Unit  To  Fight  Violent  Crime 

The  Chicago  Sun-Times  (7/8)  reports,  "Chicago  police  announced  Tuesday  it  will  create  a  citywide  violent  crime  unit  after 
three  consecutive  weekends  with  at  least  65  people  shot  and  multiple  children  killed.  The  specialized  unit  is  meant  'to  tackle 
violent  crime  and  create  community  partnerships  in  some  of  our  most  challenging  areas,'  the  department  said.  'The  ultimate 
goal  of  the  Chicago  Police  Department's  organizational  restructuring  that  began  earlier  this  year  has  always  been  to  bolster 
police  resources  under  the  authority  of  district  commanders,  while  also  being  able  to  address  spikes  in  violent  crime  citywide,' 
the  department  said."  The  Sun-Times  adds,  "Once  implemented,  the  new  unit  will  'impact'  gun,  saturation  and  gang 
enforcement  teams  in  each  of  the  city's  five  police  Areas,  the  department  said.  In  the  meantime,  police  are  bolstering  the 
Summer  Mobile  Patrol  Unit,  a  task  force  of  100  officers  focusing  on  high-crime  areas." 


After  George  Floyd's  death  and  the  response  that  followed,  police  leaders,  community  members,  and  elected 
officials  in  the  United  States  and  around  the  world  are  looking  for  collaborative,  constructive  ways  to  move  public 
safety  efforts  forward.  The  IACP  has  launched  a  new  Community-Police  Engagement  resource  page  featuring  a 
variety  of  tools  that  provide  policy  considerations  and  tangible  strategies  to  support  police  and  communities  in 
their  efforts  to  engage  in  productive  dialogue,  form  strong  partnerships,  and  identify  meaningful  solutions. 

Topics  include  community  policing;  bias  free  policing;  use  of  force;  leadership  and  culture;  and  recruitment  and 
promotional  testing.  At  a  time  when  agencies  are  looking  to  assess  their  policies  and  procedures  and  develop 
new  initiatives  to  maximize  community-police  engagement,  these  tools  provide  a  meaningful  base  to  help  public 
safety  stakeholders  develop  a  strong,  consistent  foundation. 
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CRIME  &  DRUGS 


Driver  Charged  With  Vehicular  Homicide  In  Death  Of  Seattle  Protester 

The  Washington  Post  (7/8,  Guarino)  reports,  "A  man  who  allegedly  struck  Black  Lives  Matter  protesters  in  Seattle  with  his 
car,  killing  one,  was  charged  with  reckless  driving,  vehicular  assault  and  vehicular  homicide  by  the  King  County  Prosecuting 
Attorney's  Office  on  Wednesday.  Washington  State  Patrol  and  the  FBI  are  investigating  the  case,  a  prominent  and  fatal  example 
of  recent  car  attacks  on  demonstrators."  The  Post  adds,  "When  protesters  gathered  for  a  Black  Femme  March  on  Interstate  5 
on  July  3,  it  was  the  19th  consecutive  night  activists  had  done  so,  according  to  the  state  patrol.  Near  midnight,  the  patrol  closed 
a  section  of  the  interstate  for  the  demonstration.  After  1  a.m.,  a  white  Jaguar,  seen  on  security  video  entering  the  highway 
through  an  off-ramp,  drove  through  the  group  at  high  speed,  authorities  said.  The  car  struck  two  people  -  Summer  Taylor,  a  24- 
year-old  Seattle  resident,  and  Diaz  Love,  32  -  then  fled  the  scene,  speeding  down  the  highway." 

The  New  York  Times  (7/8,  Waller,  Paybarah)  reports  that  Dawit  Kelete,  27,  "is  being  held  with  bail  set  at  $1.2  million 
and  is  expected  to  remain  in  jail,  the  King  County  Prosecuting  Attorney's  Office  said.  Two  of  the  charges,  vehicular  homicide  and 
vehicular  assault,  are  felonies,  a  spokesman  for  the  prosecuting  attorney's  office  said.  Mr.  Kelete  could  face  more  than  13  years 
in  prison,  said  the  spokesman,  Casey  McNerthney."  The  Times  adds,  "The  Washington  State  Patrol  and  the  F.B.I.  were  still 
investigating  the  matter,  and  Mr.  Kelete  could  face  additional  charges,  according  to  a  statement  from  the  prosecutor's  office." 

Crews  Of  ATM  Thieves  Using  Trucks  As  Battering  Rams  Inside  Baltimore,  Maryland  Businesses 

The  Baltimore  Sun  (7/8,  Fenton)  reports,  "Sometimes,  they  operate  with  the  speed  and  precision  of  a  NASCAR  pit  crew  - 
prying  open  the  locked  steel  gates  and  doors  of  small  businesses  around  Baltimore,  then  lifting  away  ATMs  and  hurrying  them 
to  a  waiting  pickup  truck  or  van.  Other  times,  the  thieves  use  vehicles  -  typically  stolen  -  as  battering  rams  to  force  entry.  They 
crash  through  storefronts  to  commit  a  small  bank  robbery  that  does  not  require  holding  up  a  teller."  The  Sun  adds,  "The  chaotic 
crimes  have  continued  on  and  off  for  months,  with  small  businesses  and  one  ATM  distributor  saying  it's  a  new  and  alarming 
trend.  During  the  course  of  one  hour  as  the  sun  came  up  June  27,  three  stores  were  hit  in  west,  northeast  and  midtown 
Baltimore,  including  someone  ramming  into  a  gas  station  on  Moravia  Road.  They've  used  different  methods  and  vehicles, 
causing  police  to  believe  it's  not  just  the  work  of  one  crew  and  that  others  are  getting  in  on  the  crime." 

Mexican  Drug  Cartel  Attacks  Public  Officials 

The  Wall  Street  Journal  (7/8,  Montes,  de  Cordoba,  Subscription  Publication)  reports  on  the  Jalisco  New  Generation  Cartel, 
saying  that  it  is  the  most  important  cartel  in  Mexico  and  has  mounted  direct  assaults  on  Mexican  officials  and  law  enforcement. 
According  to  the  Journal,  the  group  is  responsible  for  the  deaths  of  over  100  officials.  The  US  Drug  Enforcement  Administration 
is  offering  $10  million  for  information  leading  to  the  arrest  of  the  group's  leader  Nemesio  Oseguera. 
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